Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCug77655.
2013-10-10T10:55:06.617
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cisco | identity_services_engine_software | ≤ 1.2 | Yes |
Application | cisco | identity_services_engine_software | 1.0 | Yes |
Application | cisco | identity_services_engine_software | 1.1 | Yes |