A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device.

cve CVE-2024-20479 1 source, 1 claim · Watch

NVD writes:
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit… the claim

What it is to other things

affectscisco/identity_services_engine
NVD
made_bycisco
NVD

In words only, so not counted until a person confirms one:

affectscisco/cisco_identity_services_engine_software
NVD says “Cisco · Cisco Identity Services Engine Software”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD4.8
receipt
Source
NVD
Its words
4.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Product
product
NVDCisco Identity Services Engine Software
receipt
Source
NVD
Its words
Cisco Identity Services Engine Software
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco Identity Services Engine Software
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDCisco
receipt
Source
NVD
Its words
Cisco
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
2026-09-29 17:49 UTCCisco
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "Cisco Identity Services Engine Software",
            "vendor": "Cisco",
            "versions": [
              {
                "status": "affected",
                "version": "2.7.0"
              },
              {
                "status": "affected",
                "version": "2.7.0 p1"
              },
              {
                "status": "affected",
                "version": "2.7.0 p2"
              },
              {
                "status": "affected",
                "version": "2.7.0 p3"
              },
              {
                "status": "affected",
                "version": "2.7.0 p4"
              },
              {
                "status": "affected",
                "version": "2.7.0 p5"
              },
              {
                "status": "affected",
                "version": "2.7.0 p6"
              },
              {
                "status": "affected",
                "version": "2.7.0 p7"
              },
              {
                "status": "affected",
                "version": "2.7.0 p8"
              },
              {
                "status": "affected",
                "version": "2.7.0 p9"
              },
              {
                "status": "affected",
                "version": "2.7.0 p10"
              },
              {
                "status": "affected",
                "version": "3.0.0"
              },
              {
                "status": "affected",
                "version": "3.0.0 p1"
              },
              {
                "status": "affected",
                "version": "3.0.0 p2"
              },
              {
                "status": "affected",
                "version": "3.0.0 p3"
              },
              {
                "status": "affected",
                "version": "3.0.0 p4"
              },
              {
                "status": "affected",
                "version": "3.0.0 p5"
              },
              {
                "status": "affected",
                "version": "3.0.0 p6"
              },
              {
                "status": "affected",
                "version": "3.0.0 p7"
              },
              {
                "status": "affected",
                "version": "3.0.0 p8"
              },
              {
                "status": "affected",
                "version": "3.1.0"
              },
              {
                "status": "affected",
                "version": "3.1.0 p1"
              },
              {
                "status": "affected",
                "version": "3.1.0 p3"
              },
              {
                "status": "affected",
                "version": "3.1.0 p2"
              },
              {
                "status": "affected",
                "version": "3.1.0 p4"
              },
              {
                "status": "affected",
                "version": "3.1.0 p5"
              },
              {
                "status": "affected",
                "version": "3.1.0 p6"
              },
              {
                "status": "affected",
                "version": "3.1.0 p7"
              },
              {
                "status": "affected",
                "version": "3.1.0 p8"
              },
              {
                "status": "affected",
                "version": "3.2.0"
              },
              {
                "status": "affected",
                "version": "3.2.0 p1"
              },
              {
                "status": "affected",
                "version": "3.2.0 p2"
              },
              {
                "status": "affected",
                "version": "3.2.0 p3"
              },
              {
                "status": "affected",
                "version": "3.2.0 p4"
              },
              {
                "status": "affected",
                "version": "3.2.0 p5"
              },
              {
                "status": "affected",
                "version": "3.2.0 p6"
              },
              {
                "status": "affected",
                "version": "3.3.0"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 2"
              },
              {
                "status": "affected",
                "version": "3.3 Patch 1"
              }
            ]
          }
        ],
        "source": "psirt@cisco.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch10:*:*:*:*:*:*",
                "matchCriteriaId": "985547CA-4A84-453A-8B7F-7CB09DB598EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "DC94625A-6ED0-439B-A2DA-15A49B2FED93",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch9:*:*:*:*:*:*",
                "matchCriteriaId": "2392609B-AFEA-4BBD-99FA-E90AD4C2AE8F",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "0DB3133B-FBE4-47F3-88FD-9AC02AFB7EBB",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7A789B44-7E6C-4FE9-BD40-702A871AB8AC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "93920663-445E-4456-A905-81CEC6CA1833",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "33DA5BB8-4CFE-44BD-9CEB-BC26577E8477",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "D3AEFA85-66B5-4145-A4AD-96D1FF86B46D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "7A6A0697-6A9E-48EF-82D8-36C75E0CDFDC",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "E939B65A-7912-4C36-8799-03A1526D7BD3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "833B438F-0869-4C0D-9952-750C00702E8D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*",
                "matchCriteriaId": "E8B2588D-01F9-450B-B2E3-ADC4125E354E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*",
                "matchCriteriaId": "E41016C0-19E6-4BCC-A8DD-F6C9A2B0003E",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "7932D5D5-83E1-4BEF-845A-D0783D4BB750",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "1B818846-4A6E-4256-B344-281E8C786C43",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "A44858A2-922A-425A-8B38-0C47DB911A3C",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*",
                "matchCriteriaId": "53484A32-757B-42F8-B655-554C34222060",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*",
                "matchCriteriaId": "0CCAC61F-C273-49B3-A631-31D3AE3EB148",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*",
                "matchCriteriaId": "51AEFCE6-FB4A-4B1C-A23D-83CC3CF3FBBD",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*",
                "matchCriteriaId": "B452B4F0-8510-475E-9AE8-B48FABB4D7D3",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*",
                "matchCriteriaId": "F1B9C2C1-59A4-49A0-9B74-83CCB063E55D",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*",
                "matchCriteriaId": "DFD29A0B-0D75-4EAB-BCE0-79450EC75DD0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*",
                "matchCriteriaId": "E6C94CC4-CC08-4DAF-A606-FDAFC92720A9",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device."
      },
      {
        "lang": "es",
        "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco ISE podría permitir que un atacante remoto autenticado lleve a cabo un ataque XSS contra un usuario de la interfaz. Esta vulnerabilidad se debe a una validación insuficiente de la entrada proporcionada por el usuario por parte de la interfaz de administración basada en web de un sistema afectado. Un atacante podría aprovechar esta vulnerabilidad inyectando código malicioso en páginas específicas de la interfaz. Un exploit exitoso podría permitir al atacante ejecutar código de script arbitrario en el contexto de la interfaz afectada o acceder a información confidencial basada en el navegador. Para aprovechar esta vulnerabilidad, el atacante debe tener privilegios de administrador en un dispositivo afectado."
      }
    ],
    "id": "CVE-2024-20479",
    "lastModified": "2026-09-21T13:21:30.213",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "psirt@cisco.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "HIGH",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 1.7,
          "impactScore": 2.7,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2024-20479",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2024-08-07T00:00:00+00:00",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2024-08-07T17:15:50.930",
    "references": [
      {
        "source": "psirt@cisco.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-V2bm9JCY"
      }
    ],
    "sourceIdentifier": "psirt@cisco.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "psirt@cisco.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-79"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—

vulnerability

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have Admin privileges on an affected device.
zetlyn/cve-nvd · 2024-08-07
cvss 4.8 product Cisco Identity Services Engine Software status Analyzed vendor Cisco source