Impact
This vulnerability involves an improper privilege management flaw within the Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector. The flaw is classified under CWE‑269 and could enable an attacker with insufficient privileges to gain elevated or unrestricted rights within the affected systems. The description does not detail the specific functions that may be abused, but the impact is a potential escalation of privilege that could compromise the integrity and confidentiality of network access control decisions.
Affected Systems
Affected systems comprise Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. No specific version information is provided, so all versions delivered by Cisco that may contain the flaw should be examined for the presence of the fix. Users should verify their deployment against Cisco’s release documentation for the hardening update that addresses this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is below 1 %, suggesting a low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, which further reduces immediate operational concern. The attack vector is not explicitly stated; based on the nature of privilege management flaws, it is inferred that the vulnerability would likely require the attacker to have some level of authenticated access within the ISE environment. No public exploitation evidence or exploit code is reported in the provided data.
OpenCVE Enrichment