Impact
The vulnerability involves insufficiently protected credentials stored or transmitted by Cisco Identity Services Engine and its Passive Identity Connector. Attackers could potentially retrieve or tamper with these credentials, enabling unauthorized access to management interfaces and internal resources. Classified as a high‑severity weakness with a CVSS score of 9.9, the flaw poses serious risk to confidentiality and integrity.
Affected Systems
Affected products include Cisco’s Identity Services Engine software and the Cisco ISE Passive Identity Connector. No specific affected versions are listed, so all deployed releases of these products may be vulnerable until the hardening release is applied.
Risk and Exploitability
The EPSS score of less than 1% indicates few known exploitations, but the high CVSS score and absence from the CISA KEV list highlight a serious potential threat. The likely attack vector involves accessing or manipulating credential data that is not adequately encrypted or protected, possibly through local or remote means, potentially granting administrative privileges and compromising policy enforcement.
OpenCVE Enrichment