QID 317075
Date Published: 2021-10-25
QID 317075: Cisco Identity Services Engine (ISE) Cross-Site Scripting (XSS) Vulnerabilities (cisco-sa-ise-xss1-rgxYry2V)
A vulnerability in the web-based management interface of Cisco ISE Software could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface on an affected device.
Affected Versions:
Prior to 2.6 Patch 10
Prior to 2.7 Patch 5
Prior to 3.0 Patch 4
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
.A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Solution
Customers are advised to refer to cisco-sa-ise-xss1-rgxYry2V for more information.
Vendor References
- cisco-sa-ise-xss1-rgxYry2V -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss1-rgxYry2V
CVEs related to QID 317075
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-xss1-rgxYry2V |
|