important · Wi-Fi
An adjacent attacker can hijack Cisco ISE BYOD onboarding and enter a protected 802.1X network.
Affects
Cisco Identity Services Engine, an enterprise network-access-control and BYOD onboarding server deployed as an appliance or virtual machine.
The attacker must be in Wi-Fi range while a legitimate user is onboarding. Weak authentication during portal redirection lets the attacker spoof that user and inherit the session. Cisco has fixed releases, although previously built affected images remain accepted.