Cisco Identity Services Engine Authentication Bypass Vulnerability
Cisco patched an unauthenticated API authentication bypass in Identity Services Engine allowing attackers to access the web-based management interface.
A vulnerability in an API of Cisco Identity Services Engine (ISE) stems from insufficient authentication control on an API endpoint. An unauthenticated remote attacker can send a crafted request to bypass authentication and gain unauthorized access to the device via the web-based management interface. Cisco has released software updates and no workarounds are available.