CVE detail
CVE-2014-0680 — CVE-2014-0680
Published 2014-01-29 · Modified 2026-06-17 · Vendor cisco · Product identity_services_engine · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0195
EPSS probability
exploitation probability, 30d
78.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.
Remediation
| Product | Vulnerable range | Fixed version | Advisory |
|---|
| n/a n/a | — | not specified | advisory ↗ |
References