A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device.

zetlyn/cve-nvd vulnerability cve CVE-2024-20479 cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:* cpe cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:* known 2024-08-07

https://nvd.nist.gov/vuln/detail/CVE-2024-20479

Properties

cvss4.8
receipt
Source
NVD
Its words
4.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
productCisco Identity Services Engine Software
receipt
Source
NVD
Its words
Cisco Identity Services Engine Software
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco Identity Services Engine Software
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
statusAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
vendorCisco
receipt
Source
NVD
Its words
Cisco
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-05 18:25 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}

Text

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device. Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado.