In plain language
What this advisory means
Cisco Identity Services Engine (ISE) contains two stored cross-site scripting vulnerabilities in its guest-portal management interface. An attacker with valid administrative credentials could place malicious script code into specific interface pages. The code could then run in another user's browser within the affected interface, potentially exposing sensitive browser-based information. Cisco rates the advisory Medium with a CVSS 3.1 base score of 4.8.
Technical explanation
How the issue affects the environment
CVE-2025-20204 and CVE-2025-20205 are CWE-79 input-validation vulnerabilities in the web-based management interface for Cisco ISE guest portals. Exploitation is remote and requires valid administrative credentials and user interaction. Successful exploitation can execute arbitrary script code in the security context of the affected interface or access sensitive browser-based information. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N.
Operational impact
Why teams should care
Successful exploitation could compromise the confidentiality and integrity of information handled in a user's browser while using the affected ISE interface. Cisco's CVSS assessment indicates low confidentiality and integrity impact and no availability impact. Exploitation requires a privileged administrative account and user interaction.
Immediate action
Cisco strongly recommends migrating Cisco ISE 3.4 and earlier to the fixed release. Follow the Cisco Identity Services Engine upgrade guides when moving to Cisco ISE 3.5.
Affected and fixed releases
Temporary risk reduction
Cisco states that no workarounds address these vulnerabilities.
Evidence and validation checklist
- Cisco advisory ID: cisco-sa-ise-xss-42tgsdMG, version 1.3, last updated July 20, 2026.
- Security Impact Rating: Medium; CVSS 3.1 base score: 4.8.
- Affected deployment condition: Cisco ISE guest portals must be configured.
- Affected releases: Cisco ISE 3.4 and earlier; Cisco directs customers to migrate to a fixed release.
- Cisco ISE 3.5 is listed as not vulnerable.
- Cisco ISE Passive Identity Connector is confirmed not vulnerable.
- Exploitation requires valid administrative credentials and user interaction.
- No workarounds are available.
- Cisco PSIRT reports no known public announcements or malicious exploitation.
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
