CVE-2015-6323

critical
Published 2016-01-15 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

The Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch 4 allows remote attackers to obtain administrative access via unspecified vectors, aka Bug ID CSCuw34253.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160113-ise

Application impact

VendorProductVersionsFixed
cisco ciscoidentity_services_engine_software1.1.1
cisco ciscoidentity_services_engine_software1.1.2
cisco ciscoidentity_services_engine_software1.1.3
cisco ciscoidentity_services_engine_software1.1.4
cisco ciscoidentity_services_engine_software1.1_base
cisco ciscoidentity_services_engine_software1.2\(0.747\)
cisco ciscoidentity_services_engine_software1.2\(0.793\)
cisco ciscoidentity_services_engine_software1.2\(1.198\)
cisco ciscoidentity_services_engine_software1.2\(1.901\)
cisco ciscoidentity_services_engine_software1.2.0.899
cisco ciscoidentity_services_engine_software1.2.1
cisco ciscoidentity_services_engine_software1.2_base
cisco ciscoidentity_services_engine_software1.3\(0.722\)
cisco ciscoidentity_services_engine_software1.3\(0.876\)
cisco ciscoidentity_services_engine_software1.3\(106.146\)
cisco ciscoidentity_services_engine_software1.3\(120.135\)
cisco ciscoidentity_services_engine_software1.4\(0.109\)
cisco ciscoidentity_services_engine_software1.4\(0.181\)
cisco ciscoidentity_services_engine_software1.4\(0.253\)

References

Verify integrity in audit chain (admin only). AS-IS.