CVE-2024-20530: Cisco Identity Services Engine Reflected Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20530?
The severity of CVE-2024-20530 is classified as medium, allowing unauthenticated remote attackers to exploit the vulnerability.
How do I fix CVE-2024-20530?
To fix CVE-2024-20530, apply the latest security patches provided by Cisco for affected versions of Identity Services Engine.
Which versions of Cisco Identity Services Engine are affected by CVE-2024-20530?
CVE-2024-20530 affects Cisco Identity Services Engine versions 3.0.0 and all patch versions, as well as versions 3.1.0 through 3.4.0.
Can CVE-2024-20530 be exploited from the internet?
Yes, CVE-2024-20530 can be exploited by unauthenticated remote attackers targeting the web-based management interface over the internet.
What type of attack can be conducted through CVE-2024-20530?
CVE-2024-20530 allows attackers to conduct cross-site scripting (XSS) attacks against users of the Cisco ISE management interface.