A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
The product does not neutralize or incorrectly neutralizes user-controlled input for alternate script syntax.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Identity_services_engine | Cisco | 3.0.0 (including) | 3.0.0 (including) |
Identity_services_engine | Cisco | 3.0.0-patch1 (including) | 3.0.0-patch1 (including) |
Identity_services_engine | Cisco | 3.0.0-patch2 (including) | 3.0.0-patch2 (including) |
Identity_services_engine | Cisco | 3.0.0-patch3 (including) | 3.0.0-patch3 (including) |
Identity_services_engine | Cisco | 3.0.0-patch4 (including) | 3.0.0-patch4 (including) |
Identity_services_engine | Cisco | 3.0.0-patch5 (including) | 3.0.0-patch5 (including) |
Identity_services_engine | Cisco | 3.0.0-patch6 (including) | 3.0.0-patch6 (including) |
Identity_services_engine | Cisco | 3.0.0-patch7 (including) | 3.0.0-patch7 (including) |
Identity_services_engine | Cisco | 3.1 (including) | 3.1 (including) |
Identity_services_engine | Cisco | 3.1-patch1 (including) | 3.1-patch1 (including) |
Identity_services_engine | Cisco | 3.1-patch2 (including) | 3.1-patch2 (including) |
Identity_services_engine | Cisco | 3.1-patch3 (including) | 3.1-patch3 (including) |
Identity_services_engine | Cisco | 3.1-patch4 (including) | 3.1-patch4 (including) |
Identity_services_engine | Cisco | 3.1-patch5 (including) | 3.1-patch5 (including) |
Identity_services_engine | Cisco | 3.2 (including) | 3.2 (including) |