TL;DR π
Multiple vulnerabilities have been identified in the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow an authenticated, remote attacker to disclose sensitive information or conduct reflected cross-site scripting (XSS) attacks. Cisco has released software updates to address these issues, but no workarounds are available.
What happened π΅οΈββοΈ
Cisco has disclosed multiple vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities stem from insufficient validation of user-supplied input and improper data protection mechanisms in the web-based management interface. Attackers with authenticated access could exploit these vulnerabilities to execute arbitrary scripts or access sensitive information.