Impact
A weakness in Cisco Identity Services Engine allows an authenticated remote attacker with high‑privileged administrative credentials to send a crafted serialized Java object, exploiting insecure deserialization (CWE‑502). Successful exploitation results in remote code execution on the underlying operating system, enabling the attacker to gain user‑level access and subsequently elevate privileges to root. The attacker can also cause a denial of service in single‑node deployments, rendering the ISE node unavailable until it is restored, which in turn blocks endpoints from authenticating to the network.
Affected Systems
Cisco Identity Services Engine Software is impacted. Specific product versions are not disclosed in the advisory, so any version of ISE may be vulnerable until a patched release is applied.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. The EPSS score of <1% signifies a low but nonzero likelihood of exploitation. The vulnerability is not yet listed in CISA's KEV catalog. Exploitation requires that the attacker be authenticated with high‑privilege credentials, then send a crafted payload to the vulnerable endpoint. Once compromise occurs, the attacker can execute arbitrary commands and elevate to root, leading to full system compromise.
OpenCVE Enrichment