Impact
A vulnerability in the Cisco Identity Services Engine API allows an authenticated, remote attacker to retrieve sensitive data from an affected device. The flaw arises from insufficient validation of user-supplied parameters, enabling the attacker to send crafted API requests that return confidential information such as hashed credentials that could be leveraged for future attacks. The primary impact is the exposure of confidential data without compromising the system’s control or integrity.
Affected Systems
The affected product is Cisco Identity Services Engine Software. No specific version range is listed; the vulnerability applies to all installations that have not applied the vendor’s fix.
Risk and Exploitability
The CVSS score of 4.9 indicates medium severity, and the EPSS score of less than 1% denotes a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated remote attacker who can send API requests with valid administrative credentials. Successful exploitation would grant access to sensitive information, increasing the risk of credential theft and subsequent compromise of other network resources.
OpenCVE Enrichment