VYPR
Medium severity5.5NVD Advisory· Published Nov 6, 2024· Updated Jun 17, 2026

CVE-2024-20531

CVE-2024-20531

Description

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct a server-side request forgery (SSRF) attack through an affected device. To exploit this vulnerability, the attacker would need valid Super Admin credentials.

This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing XML input. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to read arbitrary files on the underlying operating system or conduct an SSRF attack through the affected device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

33
  • cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*+ 31 more
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.0.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch9:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*
    • cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
    • (no CPE)range: 3.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.