CVE-2018-15440 is a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE). It stems from insufficient sanitization of user-supplied data displayed in log files and web pages. An unauthenticated, remote attacker could exploit this by tricking a user into clicking a malicious link or viewing an affected log, leading to script execution in the user's browser context or sensitive information disclosure. The vulnerability has a CVSS score of 6.1 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low impact to confidentiality and integrity. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered no community discussion or media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4\(0.357\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine_software:2.4\(0.357\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.