Skip to finding
important · Wi-Fi

An adjacent attacker can hijack Cisco ISE BYOD onboarding and enter a protected 802.1X network.

Affects

Cisco Identity Services Engine, an enterprise network-access-control and BYOD onboarding server deployed as an appliance or virtual machine.

The attacker must be in Wi-Fi range while a legitimate user is onboarding. Weak authentication during portal redirection lets the attacker spoof that user and inherit the session. Cisco has fixed releases, although previously built affected images remain accepted.

Detail and 1 source
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026