Vulnerability Details CVE-2014-0681
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of report-output pages, aka Bug ID CSCui15064.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.9%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-0681
-
cpe:2.3:a:cisco:identity_services_engine_software:-
-
cpe:2.3:a:cisco:identity_services_engine_software:1.0
-
cpe:2.3:a:cisco:identity_services_engine_software:1.0.4.573
-
cpe:2.3:a:cisco:identity_services_engine_software:1.0_base
-
cpe:2.3:a:cisco:identity_services_engine_software:1.0_mr_base
-
cpe:2.3:a:cisco:identity_services_engine_software:1.1
-
cpe:2.3:a:cisco:identity_services_engine_software:1.1(4.1)
-
cpe:2.3:a:cisco:identity_services_engine_software:1.1.1
-
cpe:2.3:a:cisco:identity_services_engine_software:1.1.2
-
cpe:2.3:a:cisco:identity_services_engine_software:1.1.3
-
cpe:2.3:a:cisco:identity_services_engine_software:1.1.4
-
cpe:2.3:a:cisco:identity_services_engine_software:1.1_base
-
cpe:2.3:a:cisco:identity_services_engine_software:1.2