Impact
The flaw resides in Cisco Identity Services Engine's web‑based management interface. Certain files lack proper authorization enforcement, allowing an authenticated attacker with administrative privileges to export user data. This export surface can reveal sensitive information, including passwords that are normally hidden from administrators, thereby violating confidentiality.
Affected Systems
The vulnerability affects Cisco Identity Services Engine Software. No specific affected version numbers are provided in the advisory, so all installations using the web‑based management interface should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 4.9 indicates a medium severity. The EPSS score of less than 1 % suggests low current exploit probability. The vulnerability requires authenticated access and administrative rights, limiting the attacker to users with such privileges. Because the attack vector is internal (authenticated remote), the risk is moderate but does not pose widespread automatic exploitation. The advisory does not list the issue in the CISA KEV catalog, further indicating limited known exploitation.
OpenCVE Enrichment