CSRF Vulnerability in Cisco Identity Services Engine
CVE-2018-0413
8.8HIGH
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 1 August 2018
What is CVE-2018-0413?
A vulnerability exists in the web-based management interface of Cisco Identity Services Engine (ISE), enabling unauthenticated remote attackers to perform Cross-Site Request Forgery (CSRF) attacks. This flaw arises from inadequate CSRF protections within the management interface, allowing an attacker to trick a user into clicking a malicious link. By exploiting this vulnerability, the attacker can execute unauthorized actions on the affected device with the privileges of the authenticated user, posing a significant risk to system integrity and confidentiality. For more information, refer to Cisco Bug ID CSCvi85159.
Affected Version(s)
Cisco Identity Services Engine unknown Cisco Identity Services Engine unknown