Impact
The flaw involves incorrect transfer of resources between logical spheres within Cisco Identity Services Engine (ISE) and its Passive Identity Connector (ISE‑PIC). This may allow an attacker to move data into an unauthorized sphere, potentially exposing confidential information or enabling privilege escalation because access controls are improperly enforced.
Affected Systems
The affected products are Cisco Identity Services Engine and Cisco ISE Passive Identity Connector. The advisory does not list specific versions, so any deployment of these products that has not yet applied the hardening release could be vulnerable. The risk applies to both the core ISE appliance and the connected passive identity connector component.
Risk and Exploitability
The CVSS score of 9.1 indicates a severe threat, while the EPSS score of less than 1% suggests that exploitation is presently rare. The vulnerability is not in the CISA KEV catalog. Likely exploitation would require an authenticated session with sufficient privileges on the ISE environment; an attacker would need to trigger the improper resource transfer, possibly by manipulating configuration or exploiting a feature that moves resources between spheres. The lack of an official fix in the advisory means that vendors must be monitored for a future hardening release or patch.
OpenCVE Enrichment