CVE-2024-20530
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Nov 6, 2024
CWE ID 79
Summary
CVE-2024-20530 is a newly disclosed vulnerability affecting the web-based management interface of Cisco ISE. This issue permits an unauthenticated, remote attacker to perpetrate Cross-Site Scripting (XSS) attacks against users of the interface. The root cause of this vulnerability lies in the interface's failure to adequately validate user-supplied input. An attacker can exploit this flaw by crafting a malicious link, which, if clicked by a user, could enable the attacker to execute arbitrary script code or gain access to sensitive browser-based information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Identity Services Engine
Affected Vendors
- Cisco Systems Inc