CVE-2024-20251

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
ciscoCNA
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
ciscoidentity_services_engine
1.0
ciscoidentity_services_engine
1.0.4
ciscoidentity_services_engine
1.1
ciscoidentity_services_engine
1.1.1
ciscoidentity_services_engine
1.1.2
ciscoidentity_services_engine
1.1.3
ciscoidentity_services_engine
1.1.4
ciscoidentity_services_engine
1.2
ciscoidentity_services_engine
1.2\(1.199\)
ciscoidentity_services_engine
1.2.1
ciscoidentity_services_engine
1.3
ciscoidentity_services_engine
1.3\(0.722\)
ciscoidentity_services_engine
1.3\(0.876\)
ciscoidentity_services_engine
1.3\(0.909\)
ciscoidentity_services_engine
1.3\(106.146\)
ciscoidentity_services_engine
1.3\(120.135\)
ciscoidentity_services_engine
1.4
ciscoidentity_services_engine
1.4\(0.109\)
ciscoidentity_services_engine
1.4\(0.181\)
ciscoidentity_services_engine
1.4\(0.253\)
ciscoidentity_services_engine
1.4\(0.908\)
ciscoidentity_services_engine
2.0
ciscoidentity_services_engine
2.0\(0.147\)
ciscoidentity_services_engine
2.0\(0.169\)
ciscoidentity_services_engine
2.0\(0.222\)
ciscoidentity_services_engine
2.0\(0.234\)
ciscoidentity_services_engine
2.0\(0.249\)
ciscoidentity_services_engine
2.0\(0.306\)
ciscoidentity_services_engine
2.0\(1.130\)
ciscoidentity_services_engine
2.0.1
ciscoidentity_services_engine
2.1
ciscoidentity_services_engine
2.1\(0.474\)
ciscoidentity_services_engine
2.1\(0.476\)
ciscoidentity_services_engine
2.1\(0.800\)
ciscoidentity_services_engine
2.1\(0.904\)
ciscoidentity_services_engine
2.1\(0.907\)
ciscoidentity_services_engine
2.1\(102.101\)
ciscoidentity_services_engine
2.1\(102.103\)
ciscoidentity_services_engine
2.2
ciscoidentity_services_engine
2.2\(0.283\)
ciscoidentity_services_engine
2.2\(0.470\)
ciscoidentity_services_engine
2.2\(0.471\)
ciscoidentity_services_engine
2.2\(0.903\)
ciscoidentity_services_engine
2.2\(0.909\)
ciscoidentity_services_engine
2.2\(0.910\)
ciscoidentity_services_engine
2.2\(1.145\)
ciscoidentity_services_engine
2.2.0
ciscoidentity_services_engine
2.2.0:patch1
ciscoidentity_services_engine
2.2.0:patch10
ciscoidentity_services_engine
2.2.0:patch12
ciscoidentity_services_engine
2.2.0:patch13
ciscoidentity_services_engine
2.2.0:patch14
ciscoidentity_services_engine
2.2.0:patch15
ciscoidentity_services_engine
2.2.0:patch16
ciscoidentity_services_engine
2.2.0:patch17
ciscoidentity_services_engine
2.2.0:patch2
ciscoidentity_services_engine
2.2.0:patch3
ciscoidentity_services_engine
2.2.0:patch4
ciscoidentity_services_engine
2.2.0:patch5
ciscoidentity_services_engine
2.2.0:patch6
ciscoidentity_services_engine
2.2.0:patch7
ciscoidentity_services_engine
2.2.0:patch8
ciscoidentity_services_engine
2.2.0:patch9
ciscoidentity_services_engine
2.2.0.470
ciscoidentity_services_engine
2.2.0.470:patch1
ciscoidentity_services_engine
2.2.0.470:patch10
ciscoidentity_services_engine
2.2.0.470:patch11
ciscoidentity_services_engine
2.2.0.470:patch12
ciscoidentity_services_engine
2.2.0.470:patch13
ciscoidentity_services_engine
2.2.0.470:patch14
ciscoidentity_services_engine
2.2.0.470:patch15
ciscoidentity_services_engine
2.2.0.470:patch16
ciscoidentity_services_engine
2.2.0.470:patch2
ciscoidentity_services_engine
2.2.0.470:patch3
ciscoidentity_services_engine
2.2.0.470:patch4
ciscoidentity_services_engine
2.2.0.470:patch5
ciscoidentity_services_engine
2.2.0.470:patch6
ciscoidentity_services_engine
2.2.0.470:patch7
ciscoidentity_services_engine
2.2.0.470:patch8
ciscoidentity_services_engine
2.2.0.470:patch9
ciscoidentity_services_engine
2.3
ciscoidentity_services_engine
2.3\(0.151\)
ciscoidentity_services_engine
2.3\(0.298\)
ciscoidentity_services_engine
2.3\(0.904\)
ciscoidentity_services_engine
2.3\(0.905\)
ciscoidentity_services_engine
2.3.0
ciscoidentity_services_engine
2.3.0:patch1
ciscoidentity_services_engine
2.3.0:patch2
ciscoidentity_services_engine
2.3.0:patch3
ciscoidentity_services_engine
2.3.0:patch4
ciscoidentity_services_engine
2.3.0:patch5
ciscoidentity_services_engine
2.3.0:patch6
ciscoidentity_services_engine
2.3.0:patch7
ciscoidentity_services_engine
2.3.0.298
ciscoidentity_services_engine
2.3.0.298:patch1
ciscoidentity_services_engine
2.3.0.298:patch2
ciscoidentity_services_engine
2.3.0.298:patch3
ciscoidentity_services_engine
2.3.0.298:patch4
ciscoidentity_services_engine
2.3.0.298:patch5
ciscoidentity_services_engine
2.3.0.298:patch6
ciscoidentity_services_engine
2.3.0.298:patch7
ciscoidentity_services_engine
2.4
ciscoidentity_services_engine
2.4\(0.192\)
ciscoidentity_services_engine
2.4\(0.247\)
ciscoidentity_services_engine
2.4\(0.357\)
ciscoidentity_services_engine
2.4\(0.901\)
ciscoidentity_services_engine
2.4\(0.901.1\)
ciscoidentity_services_engine
2.4\(0.902\)
ciscoidentity_services_engine
2.4\(0.903\)
ciscoidentity_services_engine
2.4\(0.904\)
ciscoidentity_services_engine
002.004\(000.914\)
ciscoidentity_services_engine
2.4\(100.159\)
ciscoidentity_services_engine
2.4.0
ciscoidentity_services_engine
2.4.0:patch_11
ciscoidentity_services_engine
2.4.0:patch1
ciscoidentity_services_engine
2.4.0:patch10
ciscoidentity_services_engine
2.4.0:patch11
ciscoidentity_services_engine
2.4.0:patch12
ciscoidentity_services_engine
2.4.0:patch13
ciscoidentity_services_engine
2.4.0:patch14
ciscoidentity_services_engine
2.4.0:patch2
ciscoidentity_services_engine
2.4.0:patch3
ciscoidentity_services_engine
2.4.0:patch4
ciscoidentity_services_engine
2.4.0:patch5
ciscoidentity_services_engine
2.4.0:patch6
ciscoidentity_services_engine
2.4.0:patch7
ciscoidentity_services_engine
2.4.0:patch8
ciscoidentity_services_engine
2.4.0:patch9
ciscoidentity_services_engine
2.4.0.357
ciscoidentity_services_engine
2.4.0.357:patch1
ciscoidentity_services_engine
2.4.0.357:patch10
ciscoidentity_services_engine
2.4.0.357:patch11
ciscoidentity_services_engine
2.4.0.357:patch12
ciscoidentity_services_engine
2.4.0.357:patch2
ciscoidentity_services_engine
2.4.0.357:patch3
ciscoidentity_services_engine
2.4.0.357:patch4
ciscoidentity_services_engine
2.4.0.357:patch5
ciscoidentity_services_engine
2.4.0.357:patch6
ciscoidentity_services_engine
2.4.0.357:patch7
ciscoidentity_services_engine
2.4.0.357:patch8
ciscoidentity_services_engine
2.4.0.357:patch9
ciscoidentity_services_engine
2.5
ciscoidentity_services_engine
2.5\(0.1\)
ciscoidentity_services_engine
2.5\(0.225\)
ciscoidentity_services_engine
2.5\(0.353\)
ciscoidentity_services_engine
2.6
ciscoidentity_services_engine
2.6\(0.156\)
ciscoidentity_services_engine
002.006\(000.156\)
ciscoidentity_services_engine
2.6\(0.999\)
ciscoidentity_services_engine
2.6.0
ciscoidentity_services_engine
2.6.0:patch1
ciscoidentity_services_engine
2.6.0:patch10
ciscoidentity_services_engine
2.6.0:patch11
ciscoidentity_services_engine
2.6.0:patch12
ciscoidentity_services_engine
2.6.0:patch2
ciscoidentity_services_engine
2.6.0:patch3
ciscoidentity_services_engine
2.6.0:patch4
ciscoidentity_services_engine
2.6.0:patch5
ciscoidentity_services_engine
2.6.0:patch6
ciscoidentity_services_engine
2.6.0:patch7
ciscoidentity_services_engine
2.6.0:patch8
ciscoidentity_services_engine
2.6.0:patch9
ciscoidentity_services_engine
2.6.0.156:patch1
ciscoidentity_services_engine
2.6.0.156:patch2
ciscoidentity_services_engine
2.6.0.156:patch3
ciscoidentity_services_engine
2.6.0.156:patch5
ciscoidentity_services_engine
2.6.0.156:patch6
ciscoidentity_services_engine
2.6.0.156:patch7
ciscoidentity_services_engine
2.7
ciscoidentity_services_engine
2.7\(0.207\)
ciscoidentity_services_engine
2.7\(0.356\)
ciscoidentity_services_engine
2.7\(0.356\)
ciscoidentity_services_engine
002.007\(000.356\)
ciscoidentity_services_engine
2.7\(0.903\)
ciscoidentity_services_engine
2.7.0
ciscoidentity_services_engine
2.7.0:patch1
ciscoidentity_services_engine
2.7.0:patch2
ciscoidentity_services_engine
2.7.0:patch3
ciscoidentity_services_engine
2.7.0:patch4
ciscoidentity_services_engine
2.7.0:patch5
ciscoidentity_services_engine
2.7.0:patch6
ciscoidentity_services_engine
2.7.0:patch7
ciscoidentity_services_engine
2.7.0:patch8
ciscoidentity_services_engine
2.7.0:patch9
ciscoidentity_services_engine
2.7.0.356:patch1
ciscoidentity_services_engine
3.0\(0.458\)
ciscoidentity_services_engine
003.000\(000.458\)
ciscoidentity_services_engine
3.0.0
ciscoidentity_services_engine
3.0.0:patch1
ciscoidentity_services_engine
3.0.0:patch2
ciscoidentity_services_engine
3.0.0:patch3
ciscoidentity_services_engine
3.0.0:patch4
ciscoidentity_services_engine
3.0.0:patch5
ciscoidentity_services_engine
3.0.0:patch6
ciscoidentity_services_engine
3.0.0:patch7
ciscoidentity_services_engine
3.1
ciscoidentity_services_engine
3.1:patch1
ciscoidentity_services_engine
3.1:patch2
ciscoidentity_services_engine
3.1:patch3
ciscoidentity_services_engine
3.1:patch4
ciscoidentity_services_engine
3.1:patch5
ciscoidentity_services_engine
3.1:patch6
ciscoidentity_services_engine
3.1:patch7
ciscoidentity_services_engine
3.2
ciscoidentity_services_engine
3.2:patch1
ciscoidentity_services_engine
3.2:patch2
ciscoidentity_services_engine
3.2:patch3
ciscoidentity_services_engine
3.2:patch4
𝑥
= Vulnerable software versions