CVE-2014-0680: XSS
Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Systems running Cisco Identity Services Engine with the NAC Web Agent component and its HTTP control interface exposed to users are the relevant attack surface. The issue is remotely exploitable and does not require authentication.
What does an attacker need to exploit this issue?
An attacker needs to send a crafted URL to the vulnerable HTTP control interface. Successful exploitation allows injection of arbitrary web script or HTML.
How can I determine whether a deployment is affected or needs remediation?
The supplied information does not identify affected or fixed versions, configuration prerequisites beyond the HTTP control interface, or temporary mitigations. Use Cisco's advisory for Bug ID CSCui15038 to determine version-specific remediation.