PT-2026-93950 · Cisco · Cisco Identity Services Engine
CVE-2026-20071
·
Publicado
2026-09-16
·
Atualizado
2026-09-16
CVSS v3.1
3.8
Baixa
| Vetor | AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks.
This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network.
Correção
Authentication Bypass by Spoofing
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Identity Services Engine