CVE-2018-0215 describes a Cross-Site Request Forgery (CSRF) vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE). This medium-severity vulnerability (CVSS 6.3) allows an unauthenticated, remote attacker to perform arbitrary actions on an affected device by tricking an authenticated user into clicking a crafted link. While it has a low EPSS score and no known active exploitation or publicly available exploit code, successful exploitation could lead to unauthorized actions with the privileges of the targeted user. There is no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0\(0.234\)CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:2.0\(0.234\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.