CVE-2024-20251 (CNNVD-202401-1110)

MEDIUM
中文标题:
Cisco Identity Services Engine 安全漏洞
英文标题:
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could ...
CVSS分数: 4.8
发布时间: 2024-01-17 16:55:07
漏洞类型: 其他
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Cisco Identity Services Engine(ISE)是美国思科(Cisco)公司的一款环境感知平台(ISE身份服务引擎)。该平台通过收集网络、用户和设备中的实时信息,制定并实施相应策略来监管网络。 Cisco Identity Services Engine 存在安全漏洞,该漏洞源于基于 Web 的管理界面中的漏洞可能允许经过身份验证的远程攻击者对受影响设备上的界面用户执行存储型跨站脚本 (XSS) 攻击。

英文描述:

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack against a user of the interface on an affected device. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CWE类型:
CWE-79
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
Cisco Cisco Identity Services Engine Software 2.7.0 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p1 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p1:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p2 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p2:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p3 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p3:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p4 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p4:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p5 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p5:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p6 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p6:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p7 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p7:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p8 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p8:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p9 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p9:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 2.7.0 p10 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:2.7.0_p10:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p1 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p1:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p2 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p2:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p3 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p3:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p4 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p4:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p5 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p5:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p6 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p6:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p7 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p7:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.0.0 p8 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.0.0_p8:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 p1 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0_p1:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 p3 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0_p3:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 p2 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0_p2:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 p4 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0_p4:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 p5 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0_p5:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 p6 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0_p6:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.1.0 p7 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.1.0_p7:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.2.0 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.2.0:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.2.0 p1 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.2.0_p1:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.2.0 p2 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.2.0_p2:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.2.0 p3 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.2.0_p3:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.2.0 p4 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.2.0_p4:*:*:*:*:*:*:*
Cisco Cisco Identity Services Engine Software 3.3.0 - - cpe:2.3:a:cisco:cisco_identity_services_engine_software:3.3.0:*:*:*:*:*:*:*
cisco identity_services_engine 1.0 - - cpe:2.3:a:cisco:identity_services_engine:1.0:*:*:*:*:*:*:*
cisco identity_services_engine 1.0.4 - - cpe:2.3:a:cisco:identity_services_engine:1.0.4:*:*:*:*:*:*:*
cisco identity_services_engine 1.1 - - cpe:2.3:a:cisco:identity_services_engine:1.1:*:*:*:*:*:*:*
cisco identity_services_engine 1.1.1 - - cpe:2.3:a:cisco:identity_services_engine:1.1.1:*:*:*:*:*:*:*
cisco identity_services_engine 1.1.2 - - cpe:2.3:a:cisco:identity_services_engine:1.1.2:*:*:*:*:*:*:*
cisco identity_services_engine 1.1.3 - - cpe:2.3:a:cisco:identity_services_engine:1.1.3:*:*:*:*:*:*:*
cisco identity_services_engine 1.1.4 - - cpe:2.3:a:cisco:identity_services_engine:1.1.4:*:*:*:*:*:*:*
cisco identity_services_engine 1.2 - - cpe:2.3:a:cisco:identity_services_engine:1.2:*:*:*:*:*:*:*
cisco identity_services_engine 1.2\(1.199\) - - cpe:2.3:a:cisco:identity_services_engine:1.2\(1.199\):*:*:*:*:*:*:*
cisco identity_services_engine 1.2.1 - - cpe:2.3:a:cisco:identity_services_engine:1.2.1:*:*:*:*:*:*:*
cisco identity_services_engine 1.3 - - cpe:2.3:a:cisco:identity_services_engine:1.3:*:*:*:*:*:*:*
cisco identity_services_engine 1.3\(0.722\) - - cpe:2.3:a:cisco:identity_services_engine:1.3\(0.722\):*:*:*:*:*:*:*
cisco identity_services_engine 1.3\(0.876\) - - cpe:2.3:a:cisco:identity_services_engine:1.3\(0.876\):*:*:*:*:*:*:*
cisco identity_services_engine 1.3\(0.909\) - - cpe:2.3:a:cisco:identity_services_engine:1.3\(0.909\):*:*:*:*:*:*:*
cisco identity_services_engine 1.3\(106.146\) - - cpe:2.3:a:cisco:identity_services_engine:1.3\(106.146\):*:*:*:*:*:*:*
cisco identity_services_engine 1.3\(120.135\) - - cpe:2.3:a:cisco:identity_services_engine:1.3\(120.135\):*:*:*:*:*:*:*
cisco identity_services_engine 1.4 - - cpe:2.3:a:cisco:identity_services_engine:1.4:*:*:*:*:*:*:*
cisco identity_services_engine 1.4\(0.109\) - - cpe:2.3:a:cisco:identity_services_engine:1.4\(0.109\):*:*:*:*:*:*:*
cisco identity_services_engine 1.4\(0.181\) - - cpe:2.3:a:cisco:identity_services_engine:1.4\(0.181\):*:*:*:*:*:*:*
cisco identity_services_engine 1.4\(0.253\) - - cpe:2.3:a:cisco:identity_services_engine:1.4\(0.253\):*:*:*:*:*:*:*
cisco identity_services_engine 1.4\(0.908\) - - cpe:2.3:a:cisco:identity_services_engine:1.4\(0.908\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0 - - cpe:2.3:a:cisco:identity_services_engine:2.0:*:*:*:*:*:*:*
cisco identity_services_engine 2.0\(0.147\) - - cpe:2.3:a:cisco:identity_services_engine:2.0\(0.147\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0\(0.169\) - - cpe:2.3:a:cisco:identity_services_engine:2.0\(0.169\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0\(0.222\) - - cpe:2.3:a:cisco:identity_services_engine:2.0\(0.222\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0\(0.234\) - - cpe:2.3:a:cisco:identity_services_engine:2.0\(0.234\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0\(0.249\) - - cpe:2.3:a:cisco:identity_services_engine:2.0\(0.249\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0\(0.306\) - - cpe:2.3:a:cisco:identity_services_engine:2.0\(0.306\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0\(1.130\) - - cpe:2.3:a:cisco:identity_services_engine:2.0\(1.130\):*:*:*:*:*:*:*
cisco identity_services_engine 2.0.1 - - cpe:2.3:a:cisco:identity_services_engine:2.0.1:*:*:*:*:*:*:*
cisco identity_services_engine 2.1 - - cpe:2.3:a:cisco:identity_services_engine:2.1:*:*:*:*:*:*:*
cisco identity_services_engine 2.1\(0.474\) - - cpe:2.3:a:cisco:identity_services_engine:2.1\(0.474\):*:*:*:*:*:*:*
cisco identity_services_engine 2.1\(0.476\) - - cpe:2.3:a:cisco:identity_services_engine:2.1\(0.476\):*:*:*:*:*:*:*
cisco identity_services_engine 2.1\(0.800\) - - cpe:2.3:a:cisco:identity_services_engine:2.1\(0.800\):*:*:*:*:*:*:*
cisco identity_services_engine 2.1\(0.904\) - - cpe:2.3:a:cisco:identity_services_engine:2.1\(0.904\):*:*:*:*:*:*:*
cisco identity_services_engine 2.1\(0.907\) - - cpe:2.3:a:cisco:identity_services_engine:2.1\(0.907\):*:*:*:*:*:*:*
cisco identity_services_engine 2.1\(102.101\) - - cpe:2.3:a:cisco:identity_services_engine:2.1\(102.101\):*:*:*:*:*:*:*
cisco identity_services_engine 2.1\(102.103\) - - cpe:2.3:a:cisco:identity_services_engine:2.1\(102.103\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2 - - cpe:2.3:a:cisco:identity_services_engine:2.2:*:*:*:*:*:*:*
cisco identity_services_engine 2.2\(0.283\) - - cpe:2.3:a:cisco:identity_services_engine:2.2\(0.283\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2\(0.470\) - - cpe:2.3:a:cisco:identity_services_engine:2.2\(0.470\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2\(0.471\) - - cpe:2.3:a:cisco:identity_services_engine:2.2\(0.471\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2\(0.903\) - - cpe:2.3:a:cisco:identity_services_engine:2.2\(0.903\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2\(0.909\) - - cpe:2.3:a:cisco:identity_services_engine:2.2\(0.909\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2\(0.910\) - - cpe:2.3:a:cisco:identity_services_engine:2.2\(0.910\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2\(1.145\) - - cpe:2.3:a:cisco:identity_services_engine:2.2\(1.145\):*:*:*:*:*:*:*
cisco identity_services_engine 2.2.0 - - cpe:2.3:a:cisco:identity_services_engine:2.2.0:-:*:*:*:*:*:*
cisco identity_services_engine 2.2.0.470 - - cpe:2.3:a:cisco:identity_services_engine:2.2.0.470:-:*:*:*:*:*:*
cisco identity_services_engine 2.3 - - cpe:2.3:a:cisco:identity_services_engine:2.3:*:*:*:*:*:*:*
cisco identity_services_engine 2.3\(0.151\) - - cpe:2.3:a:cisco:identity_services_engine:2.3\(0.151\):*:*:*:*:*:*:*
cisco identity_services_engine 2.3\(0.298\) - - cpe:2.3:a:cisco:identity_services_engine:2.3\(0.298\):*:*:*:*:*:*:*
cisco identity_services_engine 2.3\(0.904\) - - cpe:2.3:a:cisco:identity_services_engine:2.3\(0.904\):*:*:*:*:*:*:*
cisco identity_services_engine 2.3\(0.905\) - - cpe:2.3:a:cisco:identity_services_engine:2.3\(0.905\):*:*:*:*:*:*:*
cisco identity_services_engine 2.3.0 - - cpe:2.3:a:cisco:identity_services_engine:2.3.0:-:*:*:*:*:*:*
cisco identity_services_engine 2.3.0.298 - - cpe:2.3:a:cisco:identity_services_engine:2.3.0.298:-:*:*:*:*:*:*
cisco identity_services_engine 2.4 - - cpe:2.3:a:cisco:identity_services_engine:2.4:*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.192\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.192\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.247\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.247\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.357\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.357\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.901\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.901\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.901.1\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.901.1\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.902\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.902\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.903\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.903\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4\(0.904\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(0.904\):*:*:*:*:*:*:*
cisco identity_services_engine 002.004\(000.914\) - - cpe:2.3:a:cisco:identity_services_engine:002.004\(000.914\):-:*:*:*:*:*:*
cisco identity_services_engine 2.4\(100.159\) - - cpe:2.3:a:cisco:identity_services_engine:2.4\(100.159\):*:*:*:*:*:*:*
cisco identity_services_engine 2.4.0 - - cpe:2.3:a:cisco:identity_services_engine:2.4.0:-:*:*:*:*:*:*
cisco identity_services_engine 2.4.0.357 - - cpe:2.3:a:cisco:identity_services_engine:2.4.0.357:-:*:*:*:*:*:*
cisco identity_services_engine 2.5 - - cpe:2.3:a:cisco:identity_services_engine:2.5:*:*:*:*:*:*:*
cisco identity_services_engine 2.5\(0.1\) - - cpe:2.3:a:cisco:identity_services_engine:2.5\(0.1\):*:*:*:*:*:*:*
cisco identity_services_engine 2.5\(0.225\) - - cpe:2.3:a:cisco:identity_services_engine:2.5\(0.225\):*:*:*:*:*:*:*
cisco identity_services_engine 2.5\(0.353\) - - cpe:2.3:a:cisco:identity_services_engine:2.5\(0.353\):*:*:*:*:*:*:*
cisco identity_services_engine 2.6 - - cpe:2.3:a:cisco:identity_services_engine:2.6:*:*:*:*:*:*:*
cisco identity_services_engine 2.6\(0.156\) - - cpe:2.3:a:cisco:identity_services_engine:2.6\(0.156\):*:*:*:*:*:*:*
cisco identity_services_engine 002.006\(000.156\) - - cpe:2.3:a:cisco:identity_services_engine:002.006\(000.156\):-:*:*:*:*:*:*
cisco identity_services_engine 2.6\(0.999\) - - cpe:2.3:a:cisco:identity_services_engine:2.6\(0.999\):-:*:*:*:*:*:*
cisco identity_services_engine 2.6.0 - - cpe:2.3:a:cisco:identity_services_engine:2.6.0:-:*:*:*:*:*:*
cisco identity_services_engine 2.6.0.156 - - cpe:2.3:a:cisco:identity_services_engine:2.6.0.156:patch1:*:*:*:*:*:*
cisco identity_services_engine 2.7 - - cpe:2.3:a:cisco:identity_services_engine:2.7:*:*:*:*:*:*:*
cisco identity_services_engine 2.7\(0.207\) - - cpe:2.3:a:cisco:identity_services_engine:2.7\(0.207\):*:*:*:*:*:*:*
cisco identity_services_engine 2.7\(0.356\) - - cpe:2.3:a:cisco:identity_services_engine:2.7\(0.356\):*:*:*:*:*:*:*
cisco identity_services_engine 002.007\(000.356\) - - cpe:2.3:a:cisco:identity_services_engine:002.007\(000.356\):-:*:*:*:*:*:*
cisco identity_services_engine 2.7\(0.903\) - - cpe:2.3:a:cisco:identity_services_engine:2.7\(0.903\):*:*:*:*:*:*:*
cisco identity_services_engine 2.7.0 - - cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*
cisco identity_services_engine 2.7.0.356 - - cpe:2.3:a:cisco:identity_services_engine:2.7.0.356:patch1:*:*:*:*:*:*
cisco identity_services_engine 3.0\(0.458\) - - cpe:2.3:a:cisco:identity_services_engine:3.0\(0.458\):*:*:*:*:*:*:*
cisco identity_services_engine 003.000\(000.458\) - - cpe:2.3:a:cisco:identity_services_engine:003.000\(000.458\):-:*:*:*:*:*:*
cisco identity_services_engine 3.0.0 - - cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*
cisco identity_services_engine 3.1 - - cpe:2.3:a:cisco:identity_services_engine:3.1:-:*:*:*:*:*:*
cisco identity_services_engine 3.2 - - cpe:2.3:a:cisco:identity_services_engine:3.2:-:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
cisco-sa-ISE-XSS-bL4VTML OTHER
cve.org
访问
CVSS评分详情
3.1 (cna)
MEDIUM
4.8
CVSS向量: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
机密性
LOW
完整性
LOW
可用性
NONE
时间信息
发布时间:
2024-01-17 16:55:07
修改时间:
2024-10-21 11:54:43
创建时间:
2025-11-11 15:39:03
更新时间:
2025-11-11 15:58:25
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2024-20251 2025-11-11 15:22:23 2025-11-11 07:39:03
NVD nvd_CVE-2024-20251 2025-11-11 14:59:44 2025-11-11 07:47:04
CNNVD cnnvd_CNNVD-202401-1110 2025-11-11 15:11:26 2025-11-11 07:58:25
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:58:25
vulnerability_type: 未提取 → 其他; cnnvd_id: 未提取 → CNNVD-202401-1110; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 其他
  • cnnvd_id: 未提取 -> CNNVD-202401-1110
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:47:04
affected_products_count: 34 → 124; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • affected_products_count: 34 -> 124
  • data_sources: ['cve'] -> ['cve', 'nvd']