Impact
The vulnerability arises from improper validation of input supplied to the diagnostic tools in Cisco Identity Services Engine and its Passive Identity Connector. An attacker who possesses valid administrative credentials can send specially crafted commands through the web‑based management interface, allowing the execution of arbitrary operating‑system commands with root privileges. Consequently, the attacker can gain full control of the device and, in single‑node deployments, render the affected node unavailable, causing a denial of service for all endpoints that have not yet authenticated.
Affected Systems
Cisco devices including the Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software are affected. Version information is not specified in the available data.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity, while the EPSS score of 1% suggests a low to moderate likelihood of exploitation. The vulnerability is listed as not included in the CISA KEV catalog. Exploitation requires remote access to the web interface and authenticated administrative privileges, indicating that the attack vector is remote, authenticated web‑based management. If an attacker succeeds, they can gain root level access and potentially cause a denial of service in single‑node deployments.
OpenCVE Enrichment