CNNVD-202508-610 Information

CNNVD ID

CNNVD-202508-610

CVE-2025-20331

  • CNNVD Published: 2025-08-06

Description (Chinese)

Cisco ISE和Cisco ISE-PIC都是美国思科(Cisco)公司的产品。Cisco ISE是一个 NAC 解决方案。用于管理零信任架构中的端点、用户和设备对网络资源的访问。Cisco ISE-PIC是一个组件。 Cisco ISE和Cisco ISE-PIC存在安全漏洞,该漏洞源于基于Web的管理界面输入验证不足,可能导致存储型跨站脚本攻击。

Description (English)

Cisco ISE and Cisco ISE-PIC are all Cisco products. Cisco ISE is a NAC solution. To manage endpoints, users and equipment access to network resources in the zero confidence architecture. Cisco ISE-PIC is a component. Cisco ISE and Cisco ISE-PIC had a security loophole, which stemmed from the inadequate validation of Web-based management interfaces, which could lead to storage-type cross-site script attacks.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

思科

Published

2025-08-06

Last Modified

2026-02-24

References

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise_xss_acc_cont-YsR4uT4U

Patch

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise_xss_acc_cont-YsR4uT4U

Share on: