Impact
The vulnerability in Cisco Identity Services Engine stems from the improper validation of user-supplied input, enabling an authenticated remote attacker with low‑privileged administrative credentials to conduct SQL injection attacks. A successful exploit allows the attacker to read or modify data in the underlying database, potentially compromising confidential system information and altering critical configuration data.
Affected Systems
Cisco Identity Services Engine Software is affected by this vulnerability. No specific product versions are listed in the advisory, so any installation of this software may need to be evaluated for the presence of the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is currently low. The flaw requires authenticated access, so it is not publicly exploitable; it is not listed in the CISA KEV catalog.
OpenCVE Enrichment