CVE-2021-34738: Cisco Identity Services Engine Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What are the vulnerabilities in CVE-2021-34738?
The vulnerability allows for a cross-site scripting (XSS) attack against a user of the Cisco Identity Services Engine (ISE) Software web-based management interface.
Which software versions are affected by CVE-2021-34738?
The Cisco Identity Services Engine (ISE) Software versions up to and including 2.6.0 are affected.
What is the severity of CVE-2021-34738?
The severity of this vulnerability is medium with a CVSS score of 6.1.
How can an attacker exploit CVE-2021-34738?
An attacker can exploit this vulnerability by conducting a cross-site scripting (XSS) attack against a user of the Cisco ISE Software web-based management interface.
Where can I find more information about CVE-2021-34738?
More information about this vulnerability can be found at the following reference: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss1-rgxYry2V