Impact
The vulnerability allows an authenticated user to send specially crafted data to the REST API of Cisco Identity Services Engine and its Passive Identity Connector. Improper validation of that data leads to command injection on the underlying operating system. Successful exploitation enables the attacker to run arbitrary commands with root privileges and, in single‑node environments, can bring the node down, causing a denial of service that affects network access for unauthenticated endpoints.
Affected Systems
The affected products are Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software, as published by Cisco. No specific version numbers are listed in the advisory; any installation of these products with the unpatched REST API is susceptible.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity, and the EPSS score of 1% shows that the vulnerability has a low but non‑trivial chance of being exploited in the wild. The vulnerability requires a valid administrative credential and access to the externally exposed REST API, making it an authenticated, remote attack vector. Because it can lead to privileged code execution, it represents a critical risk for any ISE deployment not yet patched, but it is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment