CVE-2019-1718: Cisco Identity Services Engine
High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.
A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of Secure Sockets Layer (SSL) renegotiation requests. An attacker could exploit this vulnerability by sending renegotiation requests at a high rate. An successful exploit could increase the resource usage on the system, eventually leading to a DoS condition. This vulnerability affects version 2.1.
Affected products
- Cisco Identity Services Engine: version 2.1(0.907) only
Published 2019-04-17. Last modified 2026-06-17.