Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
TL;DR 📌
Multiple vulnerabilities have been identified in the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow an authenticated, remote attacker to disclose sensitive information or conduct reflected cross-site scripting (XSS) attacks. Cisco has released software updates to address these issues, but no workarounds are available.
What happened 🕵️♂️
Cisco has disclosed multiple vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities stem from insufficient validation of user-supplied input and improper data protection mechanisms in the web-based management interface. Attackers with authenticated access could exploit these vulnerabilities to execute arbitrary scripts or access sensitive information.
Affected products 🖥️
- Cisco Identity Services Engine (ISE)
- Cisco ISE Passive Identity Connector (ISE-PIC)
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 3.1 and earlier | Migrate to a fixed release. | |
| 3.2 | 3.2 Patch 8 (Dec 2025) | |
| 3.3 | 3.3 Patch 8 (Nov 2025) | |
| 3.4 | 3.4 Patch 2 | |
| 3.5 | Not vulnerable. | |
| 1.0 | Initial public release. | |
| Cisco ISE | 3.2 Patch 8 (Dec 2025) | 3.1 and earlier |
| Cisco ISE | 3.3 Patch 8 (Nov 2025) | 3.2 |
| Cisco ISE | 3.4 Patch 2 | 3.3 |
| Cisco ISE | 3.4 Patch 4 | 3.4 |
Workarounds 🧯
There are no workarounds available for these vulnerabilities.
Risk in context 🎯
The highest CVSS score for these vulnerabilities is 5.4, indicating a Medium severity level. The vulnerabilities require authenticated access, but they could lead to significant information disclosure and potential exploitation through reflected XSS attacks. Organizations using affected products should prioritize upgrading to fixed software versions to mitigate risks.
Fast facts ⚡
- Vulnerabilities: Reflected XSS and information disclosure.
- CVSS Score: Highest is 5.4 (Medium).
- Exploitation: Requires authenticated access.
- Workarounds: None available.
- Fixed Software: Available in upcoming patches.
For leadership 🧭
Executive summary. Cisco ISE’s admin web interface has flaws letting an already-authenticated user run scripts in another session’s browser or extract information it shouldn’t expose. Severity is medium and no workaround exists, so this should be folded into the next scheduled patch cycle rather than treated as an emergency.
Why it matters:
- The flaw sits in the ISE web-based management interface, meaning anyone with a valid login to that console is a potential vector for reflected XSS or data exposure.
- No workaround exists, so the only mitigation is upgrading; ISE and ISE-PIC deployments running 3.1 or earlier must migrate entirely rather than patch in place.
- Fix timing is staggered across trains (3.2 Patch 8 in December, 3.3 Patch 8 in November, 3.4 Patch 2 or Patch 4 depending on starting version), so different ISE instances in the same estate may need different patch dates tracked separately.
- ISE is typically a network access control and identity policy point, so information disclosed through this interface could relate to authentication or network policy data handled by the platform.
Now / Next / Later:
- Now: Identify every ISE and ISE-PIC instance in your estate, note its current version and train, and match it against the correct first-fixed release before scheduling work.
- Next: Apply the appropriate patch for each train in your next change window: Patch 8 for 3.2 (December) or 3.3 (November), Patch 2 for 3.3-to-3.4 upgrades, or Patch 4 for existing 3.4 deployments; plan a migration path for any instance still on 3.1 or earlier.
- Later: Build ISE’s staggered per-train patch releases into your regular update tracking process so future fixes aren’t missed simply because different versions ship on different dates.