Vulnslist

find the latest Cisco vulnerabilities

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

cisco-sa-ise_xss_acc_cont-YsR4uT4U · Medium · Published · Updated

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to either modify part of the configuration of an affected device or conduct a stored cross-site scripting (XSS) attack. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise_xss_acc_cont-YsR4uT4U

Workarounds

There are no workarounds that address these vulnerabilities.

CVEsCVE-2025-20331, CVE-2025-20332
Cisco Bug IDsCSCwk14928, CSCwm03606
CVSS ScoreBase 5.4
Base 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:X/RL:X/RC:X
Base 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
Product Names From Source
Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Identity Services Engine Software known_affected cisco_csaf CVE-2025-20331, CVE-2025-20332 2
Cisco ISE Passive Identity Connector known_affected cisco_csaf CVE-2025-20331 1

Related Products

Product CVE Evidence
Cisco Identity Services Engine Software CVE-2025-20332 Cisco OpenVuln
Cisco ISE Passive Identity Connector CVE-2025-20332 Cisco OpenVuln
Cisco Identity Services Engine Software CVE-2025-20331 Cisco OpenVuln
Cisco ISE Passive Identity Connector CVE-2025-20331 Cisco OpenVuln