Vulnerability Bulletins

Cisco Identity Services Engine Vulnerabilities


System information

   
Affected software Cisco

Description

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload malicious files to the web root of the application or conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has

More info:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-j-KxpNynR?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities&vs_k=1

Standar resources

Property Value
CVE CVE-2023-20208 and CVE-2023-20272.

Version history

Version Comments Date
Ministerio de Defensa
CNI
CCN
CCN-CERT