Impact
A SQL injection flaw exists in the SXP REST API of Cisco Identity Services Engine that stems from inadequate validation of user input. An attacker who possesses valid administrative credentials can send crafted API requests that are executed directly against the underlying database. Successful exploitation enables the attacker to read confidential data or modify records, and it can also lead to service disruption; in single‑node deployments the ISE node may become unavailable, causing a denial of service for unauthenticated endpoints until the node is restored.
Affected Systems
The vulnerability affects Cisco Identity Services Engine Software that exposes the SXP REST API, particularly when the SXP service is enabled and at least one SXP connection is configured. Specific version information is not supplied in the advisory.
Risk and Exploitability
The CVSS score of 9.1 reflects the high severity of this flaw, while the EPSS score of less than 1% indicates a low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access with administrative rights, making the threat contingent upon credential compromise or insider actions. If an attacker gains such access, the impact could be significant, but the overall risk remains moderated by the credential requirement.
OpenCVE Enrichment