Impact
A vulnerability in Cisco ISE lets an unauthenticated remote attacker inject SQL commands through improper validation of user input. If exploited successfully, the attacker can alter the underlying database, potentially changing authentication rules, policies, or other critical data. The flaw therefore threatens the integrity of the platform and can undermine the security posture of an organization that relies on ISE for identity services.
Affected Systems
The affected product is Cisco Identity Services Engine Software. Version information is not included in the advisory, so any deployable ISE installation may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability that could be exploited remotely. The EPSS score of less than 1% shows that the probability of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog, implying no known mass exploitation. The likely attack vector is remote, unauthenticated, via crafted requests aimed at ISE management endpoints. If an attacker gains access, they could modify device data and compromise identity services.
OpenCVE Enrichment