« Volver al listado

CVE-2022-20967

Estado: ModificadaMedia (5.4)—

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface.

This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTML or script code within the application interface for use in further cross-site scripting attacks.

Leer descripción completaMostrar menos

Cisco has not yet released software updates that address this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-20967",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@cisco.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.7
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "Cisco",
          "product": "Cisco Identity Services Engine Software",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.0"
            },
            {
              "status": "affected",
              "version": "2.6.0 p1"
            },
            {
              "status": "affected",
              "version": "2.6.0 p2"
            },
            {
              "status": "affected",
              "version": "2.6.0 p3"
            },
            {
              "status": "affected",
              "version": "2.6.0 p5"
            },
            {
              "status": "affected",
              "version": "2.6.0 p6"
            },
            {
              "status": "affected",
              "version": "2.6.0 p7"
            },
            {
              "status": "affected",
              "version": "2.6.0 p8"
            },
            {
              "status": "affected",
              "version": "2.6.0 p9"
            },
            {
              "status": "affected",
              "version": "2.6.0 p10"
            },
            {
              "status": "affected",
              "version": "2.6.0 p11"
            },
            {
              "status": "affected",
              "version": "2.6.0 p12"
            },
            {
              "status": "affected",
              "version": "2.7.0"
            },
            {
              "status": "affected",
              "version": "2.7.0 p1"
            },
            {
              "status": "affected",
              "version": "2.7.0 p2"
            },
            {
              "status": "affected",
              "version": "2.7.0 p3"
            },
            {
              "status": "affected",
              "version": "2.7.0 p4"
            },
            {
              "status": "affected",
              "version": "2.7.0 p5"
            },
            {
              "status": "affected",
              "version": "2.7.0 p6"
            },
            {
              "status": "affected",
              "version": "2.7.0 p7"
            },
            {
              "status": "affected",
              "version": "3.0.0"
            },
            {
              "status": "affected",
              "version": "3.0.0 p1"
            },
            {
              "status": "affected",
              "version": "3.0.0 p2"
            },
            {
              "status": "affected",
              "version": "3.0.0 p3"
            },
            {
              "status": "affected",
              "version": "3.0.0 p4"
            },
            {
              "status": "affected",
              "version": "3.0.0 p5"
            },
            {
              "status": "affected",
              "version": "3.0.0 p6"
            },
            {
              "status": "affected",
              "version": "3.1.0"
            },
            {
              "status": "affected",
              "version": "3.1.0 p1"
            },
            {
              "status": "affected",
              "version": "3.1.0 p3"
            },
            {
              "status": "affected",
              "version": "3.1.0 p4"
            },
            {
              "status": "affected",
              "version": "3.1.0 p5"
            },
            {
              "status": "affected",
              "version": "3.2.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-01-20T07:15:11.673",
  "references": [
    {
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-7Q4TNYUx",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    },
    {
      "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-7Q4TNYUx",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface.\r\n\r This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTML or script code within the application interface for use in further cross-site scripting attacks.\r\n\r Cisco has not yet released software updates that address this vulnerability. "
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en la interfaz de administración basada en web de Cisco Identity Services Engine podría permitir que un atacante remoto autenticado realice ataques de cross-site scripting contra otros usuarios de la interfaz de administración basada en web de la aplicación. Esta vulnerabilidad se debe a una validación inadecuada de la entrada a una función de la aplicación antes del almacenamiento dentro de la interfaz de administración basada en web. Un atacante podría aprovechar esta vulnerabilidad creando entradas dentro de la interfaz de la aplicación que contengan código HTML o script malicioso. Un exploit exitoso podría permitir al atacante almacenar código HTML o script malicioso dentro de la interfaz de la aplicación para usarlo en futuros ataques de cross-site scripting. Cisco aún no ha publicado actualizaciones de software que aborden esta vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T04:25:33.267",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "776397EC-F775-4068-A811-D57FC2DDAF8C",
              "versionEndExcluding": "2.6.0"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B45856E-6BE4-40A7-AE2F-4F9DC9315875"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F6D1780-3306-4481-A3CD-8F7732D955CC"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00756651-F667-4E4A-8024-3EAF003A9B92"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57E9CE5A-219F-4702-9E8A-074ED35BD252"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33C600DA-4F42-415E-8E7D-6A9EC0720252"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07BF9702-0607-49A1-A82A-E4ADF1A4135F"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11AA4EC0-6F3C-45A9-9AA4-0D81876F44B5"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B4B88F0-3229-4B07-9308-C37C794595A0"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E02F0E61-FBFF-4C6D-9132-E266FF67802B"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "541EC483-540A-4080-AA69-82A0F30EE3D6"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66CAFE97-295F-48F7-A92C-A90D3B837483"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68E172B4-867E-4413-9D45-F04B52270D41"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F22FABF-2831-4895-B0A9-283B98398F43"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B83D0F20-5A43-4583-AFAF-CD9D20352437"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2887A2C0-BADA-41D3-AA6A-F10BC58AA7F9"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ADE32BD-C500-47D8-86D6-B08F55F1BBDF"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22F23314-96BE-42F6-AE07-CC13F8856029"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76265489-E5DC-46F1-9475-2FDFCEE32CF4"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9517A1B4-45BA-44DD-9122-C86BF9075EFE"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:2.7.0:patch7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BC35A24-68DB-43C5-A817-9B35018F5990"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1063044-BCD7-487F-9880-141C30547E36"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA42E65A-7207-48B8-BE1B-0B352201BC09"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75DDAF38-4D5F-4EE4-A428-68D28FC0DA96"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5FB6AA6-F8C9-48A6-BDDA-1D25C43564EB"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B3A267A-5FEA-426D-903E-BD3F4F94A1A4"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1B3207B-1B9C-41AA-8EF6-8478458462E7"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5B9E7F3-B0F2-4A6A-B939-A62E9B12CCEB"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4DB9726-532F-45CE-81FD-45F2F6C7CE51"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1:patch1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E8F0066-0EC0-41FD-80BE-55C4ED5F6B0E"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1:patch3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D1765DB-1BEF-4CE9-8B86-B91F709600EB"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.1:patch4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D1E80EF-C3FD-4F7A-B63D-0EAA5C878B11"
            },
            {
              "criteria": "cpe:2.3:a:cisco:identity_services_engine:3.2:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36722B6C-64A5-4D00-94E1-442878C37A35"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@cisco.com"
}