Impact
A software hardening release for Cisco Identity Services Engine (ISE) and its Passive Identity Connector (ISE‑PIC) addresses vulnerabilities that stem from improper input validation, identified as CWE‑20. The flaws allow untrusted data to be processed without adequate sanitization, creating a window for an attacker to supply crafted input. If exploited, this could lead to serious compromise, such as executing unauthorized code, escalating privileges, or accessing confidential configuration data. The description explicitly classifies the weakness as CWE‑20, underscoring its fundamental nature and the potential to impact multiple components of the ISE solution.
Affected Systems
The affected products are Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. Specific version ranges are not listed in the advisory, so any deployment of these products that has not applied the hardening release may be susceptible.
Risk and Exploitability
The CVSS score of 9.1 rates the vulnerability as high severity, and the EPSS score indicates a very low probability of exploitation in current environments. The issue is not listed in the CISA KEV catalog. While no explicit attack vector is detailed, it is reasonable to infer that the attacker requires some level of network or administrative access to the ISE services to supply malicious input, making local or remote unauthorized access likely necessary. Overall, the risk is significant due to the high impact potential combined with existing low exploitation likelihood.
OpenCVE Enrichment