CVE-2024-20368

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and

Severity
Medium 6.5
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.003
20.3th percentile
Discovered by
Vendor
Vendor-published field
Published
Apr 3, 2024
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the targeted user.

Weakness: CWE-352

Affected products

Vendor Product Category Matched by
Cisco Cisco Identity Services Engine (ISE) Check your version Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Identity Services Engine Software

Vendor advisory

cisco-sa-ise-csrf-NfAKXrp5

Cisco Identity Services Engine Cross-Site Request Forgery Vulnerability

Cisco’s rating: Medium (advisory CVSS 6.5) · Published Apr 3, 2024

Bug ID: CSCwf44736

The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from

Something wrong here?