Impact
The vulnerability allows an authenticated, remote attacker with high‑privileged ISE administrative credentials to execute arbitrary system commands. Insufficient validation of user‑supplied input on the HTTP interface permits the attacker to send a crafted request that is interpreted as shell commands, resulting in remote code execution. The flaw is identified as CWE‑77, leading to potential full system compromise and privilege escalation, and can additionally cause a denial‑of‑service if a single ISE node becomes unavailable.
Affected Systems
This issue affects Cisco Identity Services Engine Software. No specific version ranges are provided in the advisory, but all deployments running a vulnerable ISE installation are impacted. Administrators should verify the exact build against the Cisco security advisory for the appropriate fix.
Risk and Exploitability
The CVSS score of 9.1 classifies this as a critical vulnerability, yet the EPSS score of <1% indicates a very low probability of current exploitation in the wild, and the vulnerability is not listed in CISA's KEV catalog. Successful exploitation requires the attacker to possess valid high‑privilege ISE credentials, meaning that the threat is primarily insider or an attacker that has compromised a legitimate account. Attackers can trigger the remote code execution by dispatching a specially crafted HTTP request, and in single‑node deployments, the effect may include a denial‑of‑service that blocks network access for endpoints that have not yet authenticated.
OpenCVE Enrichment