Impact
A flaw in the IPsec Open API endpoint of Cisco Identity Services Engine allows an authenticated remote attacker to inject operating‑system commands through insufficient input validation, a classic command injection weakness identified as CWE‑78. Successful exploitation gives the attacker the same privileges as the authenticated user and, under Cisco’s own assessment, it is straightforward to elevate those rights to root. The vulnerability is expressly noted as having a high security impact rating because of that privilege escalation path.
Affected Systems
The affected product is Cisco Identity Services Engine Software. No specific version range is supplied, so any deployment that enables the IPsec Open API and runs the vulnerable code is at risk. Because the advisory does not list versions, administrators should verify whether the exposed API is present on their systems.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate‑to‑high severity, while the EPSS score of less than 1% indicates that the likelihood of public exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Exploiting it requires valid administrative credentials and a node that has more than one network interface, with at least one active IPsec tunnel. The attacker would need remote network access to the IPsec Open API endpoint, which is typically reachable over the management interface; this is an inferred but likely attack vector based on the description.
OpenCVE Enrichment