Back

CVE-2017-6747

CRITICAL

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass local authentication. The vulnerability is due to improper handling of authentication requests and policy assignment for externally authenticated users. An attacker could exploit this vulnerability by authenticating with a valid external user account that matches an internal username and incorrectly receiving the authorization policy of the internal account. An exploit could allow the attacker to have Super Admin privileges for the ISE Admin portal. This vulnerability does not affect endpoints authenticating to the ISE. The vulnerability affects Cisco ISE, Cisco ISE Express, and Cisco ISE Virtual Appliance running Release 1.3, 1.4, 2.0.0, 2.0.1, or 2.1.0. Release 2.2.x is not affected. Cisco Bug IDs: CSCvb10995.

Published: Aug 7, 2017 Modified: Jun 17, 2026
CWE-287 CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (18)

Vendor Product Version
cisco identity_services_engine 1.3\(0.722\)
cisco identity_services_engine 1.3\(0.876\)
cisco identity_services_engine 1.3\(0.909\)
cisco identity_services_engine 1.3\(106.146\)
cisco identity_services_engine 1.3\(120.135\)
cisco identity_services_engine 1.4\(0.109\)
cisco identity_services_engine 1.4\(0.181\)
cisco identity_services_engine 1.4\(0.253\)
cisco identity_services_engine 1.4\(0.908\)
cisco identity_services_engine 2.0\(0.147\)
cisco identity_services_engine 2.0\(0.169\)
cisco identity_services_engine 2.0\(0.222\)
cisco identity_services_engine 2.0\(1.130\)
cisco identity_services_engine 2.0_base
cisco identity_services_engine 2.1\(0.474\)
cisco identity_services_engine 2.1\(0.800\)
cisco identity_services_engine 2.1\(102.101\)
cisco identity_services_engine 2.1_base

GitHub Security Advisory GHSA-4742-8cjm-26f3

A vulnerability in the authentication module of Cisco Identity Services Engine (ISE) could allow...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 5.48%

Top 8% most likely to be exploited

Threat Score 40.8 / 100

Data Sources

NVD EPSS GitHub