Impact
A flaw in the SSID bring-your-own-device onboarding workflow of Cisco Identity Services Engine allows an attacker to impersonate a legitimate user and hijack the onboarding session, granting unauthorized access to protected 802.1X networks. The weakness is a lack of proper authentication checks while a user is being onboarded, enabling session takeover. The impact is limited to gaining access to the target user's network resources, but it could be used to laterally move within the environment if the protected network hosts critical assets.
Affected Systems
The vulnerability affects Cisco Identity Services Engine Software. No specific versions are enumerated in the advisory, so all supported releases should be evaluated against the vendor’s patch schedule.
Risk and Exploitability
The CVSS score of 3.8 indicates low severity, and the EPSS score of less than 1% signals a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated adjacent attacker on the local network who can manipulate the BYOD onboarding flow, as the description infers a lack of authentication checks during the onboarding redirect to the guest web portal.
OpenCVE Enrichment