rootpwn

low · CVSS v3 3.8

CVE-2026-20071

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco Identity Services Engine (ISE) allows an unauthenticat

Overview

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco Identity Services Engine (ISE) allows an unauthenticated, adjacent attacker to hijack an active onboarding session. The flaw results from insufficient authentication checks during the device onboarding phase. Exploitation enables the attacker to gain unauthorized access to protected 802.1X enterprise networks.

Description

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks. This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network.

Impact

Adjacent attackers can take over user sessions during onboarding to gain unauthorized entry into 802.1X protected networks, compromising network access controls, confidentiality, and integrity.

Remediation

Apply software updates from Cisco to patched versions of Cisco ISE. In the interim, ensure network segmentation limits exposure on guest and onboarding VLANs, and monitor adjacent network traffic for unexpected web portal redirections.

Risk context

Assessed with a Low severity (CVSS v3: 3.8) because exploitation requires the attacker to be on the same physical or logical network segment (adjacent vector) and accurately time the attack during an active user onboarding event.

Affected products

  • Cisco Identity Services Engine (ISE)

Scores

Severity
low
CVSS v2
3.3
CVSS v3
3.8
CVSS v4
EPSS

Cisco ISE BYOD Session Hijacking 802.1X Network Security

← All CVEs