First published: Wed Jan 10 2024(Updated: )
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.This vulnerability exists because the
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine (ISE) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-ISE-XSS-bL4VTML is rated as high due to the potential for stored cross-site scripting attacks.
To fix cisco-sa-ISE-XSS-bL4VTML, upgrade to the latest version of Cisco Identity Services Engine that addresses this vulnerability.
Cisco Identity Services Engine users who have the web-based management interface are affected by cisco-sa-ISE-XSS-bL4VTML.
An attacker can perform a stored cross-site scripting attack, potentially gaining access to sensitive user data.
Yes, an attacker must be authenticated to exploit the cisco-sa-ISE-XSS-bL4VTML vulnerability.