Known vulnerabilities in ISE Passive Identity Connector (ISE-PIC)

Software CPE: cpe:2.3:a:cisco_systems:ise_passive_identity_connector:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting ISE Passive Identity Connector (ISE-PIC) ISE Passive Identity Connector (ISE-PIC) is affected by 13 known vulnerabilities: 2 medium, 11 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU138321 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20146
CWE-22 Low
No
No
- 17.07.2026 SB2026071781
#VU134760 - Improper input validation
CVE-2026-20181
CWE-20 Low
No
No
3.3 Patch 11, 3.4 Patch 6, 3.5 Patch 4 17.06.2026 SB2026061768
#VU134761 - Improper Authorization
CVE-2026-20190
CWE-285 Medium
No
No
3.4 Patch 6, 3.5 Patch 3 17.06.2026 SB2026061768
#VU126401 - Improper Encoding or Escaping of Output
CVE-2026-20136
CWE-116 Low
No
No
3.3 Patch 11, 3.4 Patch 6 17.04.2026 SB2026041754
#VU126397 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-20148
CWE-22 Low
No
No
3.1 Patch 11, 3.2 Patch 10, 3.3 Patch 11, 3.4 Patch 6 17.04.2026 SB2026041753
#VU126396 - Command injection
CVE-2026-20147
CWE-77 Medium
No
No
3.1 Patch 11, 3.2 Patch 10, 3.3 Patch 11, 3.4 Patch 6 17.04.2026 SB2026041753
#VU121600 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-20047
CWE-79 Low
No
No
3.2 Patch 8, 3.3 Patch 8, 3.4 Patch 4 15.01.2026 SB2026011561
#VU121071 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2026-20029
CWE-611 Low
No
No
3.2 Patch 8, 3.3 Patch 8, 3.4 Patch 4 07.01.2026 SB2026010779
#VU113732 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-20331
CWE-79 Low
No
No
3.1P10, 3.3P4 07.08.2025 SB2025080725
#VU113015 - Authentication Bypass by Assumed-Immutable Data
CVE-2025-20285
CWE-302 Low
No
No
3.3 Patch 7, 3.4 Patch 2 17.07.2025 SB2025071716
#VU113014 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-20284
CWE-74 Low
No
No
3.3 Patch 7, 3.4 Patch 2 17.07.2025 SB2025071716
#VU113013 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2025-20283
CWE-74 Low
No
No
3.3 Patch 7, 3.4 Patch 2 17.07.2025 SB2025071716
#VU110216 - Improper Access Control
CVE-2025-20130
CWE-284 Low
No
No
3.1 P10, 3.2 P7, 3.3 P3 05.06.2025 SB2025060527