Back to Database
Status published
Medium
CVE-2023-20208
A vulnerability in the web-based management interface of Cisco ISE...
Vulnerability Description
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of the web-based management interface of an affected device.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-20208
Credits & Attribution
No credits recorded in the NVD database.
More from Cisco
View All →CVE-2025-20393
Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability
Critical
10
CVE-2025-20377
Cisco Unified Intelligence Center API Information Disclosure Vulnerability
Medium
4.3
CVE-2025-20376
Cisco Unified Contact Center Express Remote Code Execution Vulnerability
Medium
6.5
CVE-2025-20375
Cisco Unified Contact Center Express Arbitrary File Upload Vulnerability
Medium
6.5
CVE-2025-20374
Cisco Unified Contact Center Express Arbitrary File Download Vulnerability
Medium
4.9
Affected Vendor
Cisco
View all reports →Affected Software
Cisco Identity Services Engine Software
Vulnerable Versions:
3.0.0, 3.0.0 p1, 3.0.0 p2, 3.0.0 p3, 3.0.0 p4, 3.0.0 p5, 3.0.0 p6, 3.0.0 p7, 3.1.0, 3.1.0 p1, 3.1.0 p3, 3.1.0 p4, 3.1.0 p5
Timeline
Official Publish:
November 21st, 2023
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.