Cisco Identity Services Stored Cross-Site Scripting Vulnerability
TL;DR π
- A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious codeβ¦
- No fixed release listed yet; apply mitigations and monitor.
- Workarounds are documented in the advisory.
- CVEs: CVE-2025-20267.
What happened π΅οΈββοΈ
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected products π₯οΈ
At the time of publication, this vulnerability affected Cisco ISE, regardless of device configuration.
For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.
Fixed software π§
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 3.1 and earlier | Migrate to a fixed release. | |
| 3.2 | 3.2P8 (future release) | |
| 3.3 | 3.3P5 | |
| 3.4 | 3.4P1 | |
| 1.1 | Updated the 3.2 fixed release information. | |
| 1.0 | Initial public release. |
Workarounds π§―
There are no workarounds that address this vulnerability.
Risk in context π―
Use vendor CVSS for prioritization. Consider exposure and asset criticality.
Fast facts β‘
- Advisory: cisco-sa-ise-stored-xss-Yff54m73
- Initial release: 2025-05-21T16:00:00 UTC
- Last updated: 2025-06-30T15:08:59 UTC
For leadership π§
Executive summary. Cisco ISE’s admin web console has a stored cross-site scripting flaw that lets one logged-in administrator plant malicious script for another to unknowingly execute. There is no workaround, so this needs a patch scheduled through normal change control rather than urgent emergency action.
Why it matters:
- The flaw sits in the ISE web-based management interface, the console used to configure network access policy across an organisation’s switches, wireless controllers and VPN.
- A successful injection lets the attacker run arbitrary script in the context of another admin’s session or read browser-based session data, potentially undermining the integrity of the identity and access control platform itself.
- Cisco has confirmed there is no workaround, so remediation depends entirely on moving to a fixed release.
- Versions 3.1 and earlier have no fix and must be migrated to a supported train; 3.2, 3.3 and 3.4 each need their own specific fixed build.
Now / Next / Later:
- Now: Check which ISE release train is running in your environment and confirm whether it is 3.1 or earlier, which has no fix and requires migration rather than patching.
- Next: Schedule an upgrade to the first fixed release for your train β 3.2P8, 3.3P5 or 3.4P1 β during your next maintenance window, since no interim workaround exists.
- Later: Build ISE version tracking into routine patch-cycle reviews so future admin-interface fixes are applied on a predictable schedule rather than reacting advisory by advisory.