Vulnerabilities > Cisco > Identity Services Engine > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-07-04 CVE-2017-6701 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.1(102.101)
A vulnerability in the web application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system.
network
low complexity
cisco CWE-79
6.1
2017-07-04 CVE-2017-6605 Cross-site Scripting vulnerability in Cisco Identity Services Engine 2.1(0.800)
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a reflective cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
5.4