PT-2026-93950 · Cisco · Cisco Identity Services Engine

CVE-2026-20071

·

Publicado

2026-09-16

·

Atualizado

2026-09-16

CVSS v3.1

3.8

Baixa

VetorAV:A/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks.  
This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network.

Correção

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-20071

Produtos afetados

Cisco Identity Services Engine