CVE-2025-20205

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Feb 5, 2025
CWE ID 79

Summary

CVE-2025-20205 is a vulnerability affecting the web-based management interface of Cisco Identity Services Engine (ISE). This issue permits authenticated, remote attackers to carry out cross-site scripting (XSS) attacks against users of the interface. The vulnerability arises due to inadequate input validation by the interface, enabling attackers to inject malicious code into specific pages. Successful exploitation can lead to the execution of arbitrary script code in the context of the affected interface or the access of sensitive browser-based information. To exploit this weakness, an attacker must hold valid administrative credentials.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Identity Services Engine

Affected Vendors

  • Cisco