Impact
A missing server‑side validation check in the web‑based management interface of Cisco Identity Services Engine (ISE) allows an authenticated attacker with administrative credentials to submit crafted HTTP requests that modify configuration settings. The flaw enables intentional alteration of file descriptions on a specific page, effectively granting the attacker the ability to change parts of the device configuration beyond what standard permissions should allow.
Affected Systems
The vulnerability affects Cisco Identity Services Engine Software. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to be authenticated as an administrator and to send a crafted HTTP request to the ISE web interface; server‑side validation of administrator permissions is absent, allowing configuration changes that should have been restricted.
OpenCVE Enrichment