CVE-2022-20966 is a stored cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE). An authenticated, remote attacker could exploit this by injecting malicious HTML or script code into application entries due to improper input validation. This vulnerability has a CVSS score of 5.4 (Medium), indicating that while it requires user interaction and authentication, it could lead to limited impact on confidentiality and integrity. Currently, there are no known public exploits or active exploitation, and Cisco has not yet released software updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:2.6.0:-:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch1:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch10:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:2.6.0:patch11:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.