Impact
The CVE describes an improper neutralization of special elements that can cause input containing special characters to be mishandled during processing. This flaw falls under CWE‑74 and suggests that malicious data could be injected or rendered in a way that bypasses normal escaping or filtering mechanisms. While the advisory does not explicitly confirm that arbitrary code execution would result, the nature of the weakness indicates a potential for content or script injection, which could subsequently lead to credential theft, defacement, or other misbehaviors.
Affected Systems
The affected products are Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE‑PIC). The advisory does not list specific version numbers, so all current installations may be vulnerable until the hardening release is applied.
Risk and Exploitability
The CVSS score of 10.0 ranks this flaw as critical, but the EPSS score of less than 1 % and the absence from the CISA KEV catalog suggest a low likelihood of widespread exploitation at present. The most likely attack vector would involve the web interface or API endpoints that accept user-supplied data, although this is an inferred scenario based on the nature of the flaw and is not directly stated in the advisory.
OpenCVE Enrichment