CVE-2022-20733: Cisco Identity Services Engine Authentication Bypass Vulnerability
A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20733?
CVE-2022-20733 is a vulnerability in the login page of Cisco Identity Services Engine (ISE) that allows an unauthenticated attacker to log in without credentials and access all roles without any restrictions.
What is the severity of CVE-2022-20733?
The severity of CVE-2022-20733 is critical, with a severity value of 9.8.
How does CVE-2022-20733 affect Cisco Identity Services Engine?
CVE-2022-20733 affects Cisco Identity Services Engine versions 3.1 and 3.1-patch1.
How can an unauthenticated attacker exploit CVE-2022-20733?
An unauthenticated attacker can exploit CVE-2022-20733 by leveraging the exposed sensitive Security Assertion Markup Language (SAML) metadata on the login page of Cisco Identity Services Engine.
Is there a fix for CVE-2022-20733?
Yes, Cisco has released a security advisory with remediation steps for CVE-2022-20733.