VDB

CVE-2022-20966

CVE-2022-20966 PUBLISHED CVSS 5.400000095367432 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnerability is due to improper validation of input to an application feature before storage within the web-based management interface. An attacker could exploit this vulnerability by creating entries within the application interface that contain malicious HTML or script code. A successful exploit could allow the attacker to store malicious HTML or script code within the application interface for use in further cross-site scripting attacks. Cisco has not yet released software updates that address this vulnerability.

EPSS 0.30% · 53.4th percentile

Risk Scores

CVSS 3.1
5.400000095367432
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.30%
53.4th percentile

Affected Products

VendorProductVersions
CiscoCisco Identity Services Engine Software2.6.0 p1, 2.6.0 p2, 2.6.0 p3
ciscoidentity_services_engine0, 2.6.0, 2.6.0

Exploit Intelligence

Timeline

  • Nov 17, 2022 CVE Published
  • Jan 20, 2023 EPSS Score
  • Mar 2, 2023 EPSS Score
  • Apr 11, 2023 EPSS Score
  • May 22, 2023 EPSS Score
  • Jul 1, 2023 EPSS Score
  • Sep 20, 2023 EPSS Score
  • Oct 31, 2023 EPSS Score
  • Dec 10, 2023 EPSS Score
  • Jan 20, 2024 EPSS Score
  • Apr 10, 2024 EPSS Score
  • May 21, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›