CVE-2015-4266
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The web interface in Cisco Identity Services Engine (ISE) 1.1(4.1), 1.3(106.146), and 1.3(120.135) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCut04556.
La interfaz web en Cisco Identity Services Engine (ISE) 1.1 (4.1), 1.3 (106.146) y 1.3 (120.135) no restringe correctamente el uso de elementos IFRAME, lo que facilita a atacantes remotos llevar a cabo ataques de clickjacking y otros ataques no especificados a través de una página web manipulada, relacionados con una cuestión de 'cross-frame scripting (XFS)', también conocido como Bug ID CSCut04556.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-04 CVE Reserved
- 2015-07-16 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1032930 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/viewAlert.x?alertId=39871 | 2017-09-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Identity Services Engine Software Search vendor "Cisco" for product "Identity Services Engine Software" | 1.1\(4.1\) Search vendor "Cisco" for product "Identity Services Engine Software" and version "1.1\(4.1\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Software Search vendor "Cisco" for product "Identity Services Engine Software" | 1.3\(106.146\) Search vendor "Cisco" for product "Identity Services Engine Software" and version "1.3\(106.146\)" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Software Search vendor "Cisco" for product "Identity Services Engine Software" | 1.3\(120.135\) Search vendor "Cisco" for product "Identity Services Engine Software" and version "1.3\(120.135\)" | - |
Affected
|