First published: Wed Aug 21 2024(Updated: )
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.This vulnerability is due to
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Identity Services Engine (ISE) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-ise-csrf-y4ZUz5Rj is classified as medium risk.
cisco-sa-ise-csrf-y4ZUz5Rj allows attackers to conduct cross-site request forgery (CSRF) attacks, enabling them to perform arbitrary actions on the device.
To fix cisco-sa-ise-csrf-y4ZUz5Rj, apply the recommended patches or updates from Cisco for your version of Identity Services Engine.
The affected product for cisco-sa-ise-csrf-y4ZUz5Rj is Cisco Identity Services Engine (ISE).
No, cisco-sa-ise-csrf-y4ZUz5Rj can be exploited by unauthenticated remote attackers.