CVE-2021-40121: Cisco Identity Services Engine Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40121?
CVE-2021-40121 is a vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software that could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
What is the severity of CVE-2021-40121?
The severity of CVE-2021-40121 is medium with a CVSS score of 4.8.
How does CVE-2021-40121 affect Cisco Identity Services Engine?
CVE-2021-40121 affects multiple versions of Cisco Identity Services Engine (ISE) Software, including version 2.6 and 2.7.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-40121?
The CWE ID for CVE-2021-40121 is CWE-79, which represents cross-site scripting (XSS) vulnerabilities.
How can I fix CVE-2021-40121?
To fix CVE-2021-40121, it is recommended to upgrade to a fixed version of Cisco Identity Services Engine (ISE) Software.