CSCwh70696 - Cisco ISE Stored Cross-Site Scripting Vulnerability
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-19-2024 12:46 AM
Dear All,
Recently, there is a vulnerability found called cross-site scripting(CVE-2024-20251) in ISE and as per cisco article fixed release is mentioned below which is little confusing about the fixed version. For instance, who has 2.7 version so which version has vulnerability fix that is not clearly mentioned in below table.
Can someone address the same and mentioned the version which has the vulnerability fix for version 2.7. Since in below table simply mentioned "Migrate to a fixed release" for 2.7 and 3.0 but which version has to migrate its no mentioned.
May be, I have missed something. Appreciate if someone can elaborate. Thanks.
Cisco ISE Release First Fixed Release
2.7 and earlier | Migrate to a fixed release. |
3.0 | Migrate to a fixed release. |
3.1 | 3.1P8 |
3.2 | 3.2P5 (Mar 2024) |
3.3 | 3.3P1 |
- Labels:
-
Cisco Bugs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-19-2024 06:18 AM
- As for the older releases 2.7 and 3.0 ; fix was probably still in development ; the full bug report seems rather clear
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwh70696
Known Fixed Releases (2 of 2)
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2024 09:39 PM
Hi Marce,
Thank you.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-19-2024 06:22 AM
Migrate to fixed release means they are not planning to patch those versions as they are end of support, so to get the fix you would need to upgrade to at least 3.1 or higher.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2024 09:39 PM
Hi Dustin,
Thank you.
