← Vulnerability feed

Vulnerability record · CVE-2018-0289 · published 17 May 2018

CVE-2018-0289: Cisco identity services engine software cross-site scripting vulnerability

Cisco · Identity Services Engine Software

A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of requests stored in logs in the application management interface. An attacker could exploit this vulnerability by sending malicious requests to the targeted system. An exploit could allow the attacker to conduct cross-site scripting attacks when an administrator views the log files. Cisco Bug IDs: CSCvh11308.

6.1 CVSS 3.0 Medium EPSS 1.7% · top 23.1% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the logs component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of requests stored in logs in the application management interface. An attacker could exploit this vulnerability by sending malicious requests to the targeted system. An exploit could allow the attacker to conduct cross-site scripting attacks when an administrator views the log files. Cisco Bug IDs: CSCvh11308.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-0289 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-3290Cisco identity services engine vulnerabilityCisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or pe…EPSS 2.3%9.8CVE-2015-6323Cisco identity services engine software vulnerabilityThe Admin portal in Cisco Identity Services Engine (ISE) 1.1.x, 1.2.0 before patch 17, 1.2.1 before patch 8, 1.3 before patch 5, and 1.4 before patch…EPSS 3.0%9.0CVE-2013-5530Cisco identity services engine software os command injection vulnerabilityThe web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1.1.2 before 1.1.2.145-10, 1.1.…EPSS 2.3%8.8CVE-2018-0413Cisco identity services engine software cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…EPSS 1.2%8.8CVE-2017-3835Cisco identity services engine software sql injection vulnerabilityA vulnerability in the sponsor portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access notices owned b…EPSS 1.8%7.5CVE-2017-12316Cisco identity services engine software improper authentication vulnerabilityA vulnerability in the Guest Portal login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform mul…EPSS 2.0%7.5CVE-2016-1402Cisco identity services engine software memory buffer overflow vulnerabilityThe Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorizati…EPSS 2.0%6.8CVE-2015-4267Cisco identity services engine software cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(0.793), 1.3(0.876), 1.4(0.109), 2.0(…EPSS 1.00%

Source: NIST National Vulnerability Database (record CVE-2018-0289), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.