cisco-sa-ise-csrf-y4ZUz5Rj: Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.This vulnerability is due to
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ise-csrf-y4ZUz5Rj?
The severity of cisco-sa-ise-csrf-y4ZUz5Rj is classified as medium risk.
What types of attacks are possible due to cisco-sa-ise-csrf-y4ZUz5Rj?
cisco-sa-ise-csrf-y4ZUz5Rj allows attackers to conduct cross-site request forgery (CSRF) attacks, enabling them to perform arbitrary actions on the device.
How do I fix cisco-sa-ise-csrf-y4ZUz5Rj?
To fix cisco-sa-ise-csrf-y4ZUz5Rj, apply the recommended patches or updates from Cisco for your version of Identity Services Engine.
Which Cisco product is affected by cisco-sa-ise-csrf-y4ZUz5Rj?
The affected product for cisco-sa-ise-csrf-y4ZUz5Rj is Cisco Identity Services Engine (ISE).
Can cisco-sa-ise-csrf-y4ZUz5Rj be exploited by authenticated users?
No, cisco-sa-ise-csrf-y4ZUz5Rj can be exploited by unauthenticated remote attackers.