Impact
A path traversal flaw exists in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector. The flaw originates from improper validation of user-supplied input in HTTP requests. An attacker who holds valid administrative credentials can craft a request that bypasses the check, causing the underlying operating system to resolve a crafted path. Successful exploitation permits the attacker to read or delete arbitrary files on the system, compromising the confidentiality and integrity of the appliance.
Affected Systems
The vulnerability affects Cisco’s Identity Services Engine Software and the ISE Passive Identity Connector. No specific version numbers are listed; all unpatched installations are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% implies a low probability of exploitation. The vulnerability is not included in the CISA KEV catalog. An attacker must be authenticated with administrative privileges, so the exposure is limited to insiders or compromised accounts. Exploitation requires sending a crafted HTTP request; if successful, the attacker can read or delete sensitive files on the appliance’s storage.
OpenCVE Enrichment