Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +1 more
- <= 3.1
- <= 3.2
- <= 3.3
- <= 3.4
A reflected cross-site scripting vulnerability has been identified in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). This vulnerability allows an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. The issue arises from insufficient validation of user-supplied input, enabling attackers to inject malicious code into specific pages. Exploitation could result in the execution of arbitrary scripts in the context of the affected interface or access to sensitive browser-based information.
Successful exploitation allows for reflected cross-site scripting, where an attacker can inject and execute malicious scripts in the context of the user's browser session.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found on the Cisco Identity Services Engine support page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.