CVE-2014-0680
Cisco Identity Services Engine - Cross-Site Scripting via NAC Web Agent HTTP Control Interface
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.
References (6)
Core 6
Core References
Various Sources x_refsource_confirm
http://tools.cisco.com/security/center/viewAlert.x?alertId=32617
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0680
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/65227
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/102588
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56672
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1029701
Scores
EPSS
0.0195
EPSS Percentile
78.1%
Details
CWE
CWE-79
Status
published
Products (1)
cisco/identity_services_engine
Published
Jan 29, 2014
Tracked Since
Feb 18, 2026