First published: Wed Nov 06 2024(Updated: )
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct an authorization bypass attack and cross-site scripting (XSS) attacks against a user of the web-based management interface on an affected device.For more information about these vulnerabilities, see the Details section of this advisory.Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-BBRf7mkE
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine (ISE) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-ise-auth-bypass-BBRf7mkE is critical due to the potential for remote attackers to exploit vulnerabilities.
To fix cisco-sa-ise-auth-bypass-BBRf7mkE, users should update their Cisco Identity Services Engine to the latest secure version as recommended by Cisco.
cisco-sa-ise-auth-bypass-BBRf7mkE includes vulnerabilities that allow for authorization bypass and cross-site scripting attacks.
Organizations using or managing Cisco Identity Services Engine are affected by the vulnerabilities outlined in cisco-sa-ise-auth-bypass-BBRf7mkE.
Attackers can conduct authorization bypass and cross-site scripting (XSS) attacks against users of the web-based management interface.