Impact
A flaw in the web‑based management interface of Cisco Identity Services Engine (ISE) and its Passive Identity Connector (ISE‑PIC) allows an attacker with valid administrator credentials to send crafted HTTP requests that bypass server‑side permission checks. By exploiting this weakness an attacker can alter configuration entries, such as the descriptions of files displayed on a particular page, effectively changing how the system is presented and potentially turning legitimate configuration into a malicious one. The vulnerability demonstrates a classic authorization bypass (CWE‑285) and does not allow arbitrary code execution or denial of service.
Affected Systems
The vulnerability affects Cisco’s ISE Passive Identity Connector and Cisco Identity Services Engine Software. No specific version numbers are listed, implying that all released versions prior to the patch are susceptible. Administrators should verify whether their deployed ISE or ISE‑PIC images match the affected release set advertised in Cisco’s advisory.
Risk and Exploitability
The CVSS score of 4.3 places this flaw in the medium severity range, and an EPSS score of less than 1% indicates a very low exploitation probability under current conditions. The issue is not listed in CISA’s KEV catalog, suggesting no active exploitation campaigns reported yet. Nevertheless, because the attack requires authentic administrator credentials, the threat surface is limited to attackers who have already compromised or stolen such credentials, or who successfully lure an admin into authenticating to a malicious endpoint. If the environment does not enforce MFA or strict administrative role separation, the risk escalates, and patching is strongly advised.
OpenCVE Enrichment