CVE-2023-20085
Published on: Not Yet Published
Last Modified on: 03/10/2023 04:58:00 AM UTC
CVE-2023-20085 - advisory for cisco-sa-ise-xss-ubfHG75C
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Identity Services Engine from Cisco contain the following vulnerability:
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script in the context of the affected interface or access sensitive, browser-based information.
- CVE-2023-20085 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Identity Services Engine Software version = 3.2.0
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerability | sec.cloudapps.cisco.com text/html |
![]() |
Related QID Numbers
- 317290 Cisco Identity Services Engine (ISE) Stored Cross-Site Scripting (XSS) Vulnerability (cisco-sa-ise-xss-ubfHG75C)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Identity Services Engine | 3.2 | - | All | All |
- cpe:2.3:a:cisco:identity_services_engine:3.2:-:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Cisco ISE Software の Web 管理インターフェイスの処理にクロスサイトスクリプティングの問題 (CVE-2023-20085) [45053] sid.softek.jp/content/show/4… #SIDfm #脆弱性情報 | 2023-02-17 08:30:06 |
![]() |
Cisco Identity Services Engine cross-site scripting | CVE-2023-20085 - redpacketsecurity.com/cisco-identity… #CVE #Vulnerability… twitter.com/i/web/status/1… | 2023-02-17 10:05:44 |
![]() |
CVE-2023-20085 : A vulnerability in the web-based management interface of Cisco Identity Services Engine ISE coul… twitter.com/i/web/status/1… | 2023-03-01 08:07:29 |
![]() |
[MEDIUM] CVE Report on March 10, 2023 12:14 [1/3] | 2023-03-10 12:14:44 |
![]() |
[MEDIUM] CVE Report on March 10, 2023 11:59 [1/3] | 2023-03-10 11:59:21 |