Impact
The vulnerability stems from insecure deserialization of a user‑supplied Java byte stream in the web‑based management interface of Cisco Identity Services Engine. An authenticated attacker with low‑privileged administrative rights can send a crafted serialized object that is executed on the host, enabling arbitrary command execution and privilege elevation to root. The flaw can also lead to a denial of service by crashing the ISE node in single‑node deployments, preventing endpoints from authenticating until the system is restored.
Affected Systems
Cisco Identity Services Engine software is affected. The advisory does not list specific build versions, indicating that all current releases that include the vulnerable deserialization logic may be impacted. Administrators should check Cisco’s current patch or upgrade for the ISE product to ensure protection.
Risk and Exploitability
The CVSS score of 9.9 classifies this flaw as critical. Although the EPSS probability is less than 1%, the combination of a high severity score, the requirement for only low‑privileged authentication, and the remote attack vector via the management interface make it a high risk scenario. The vulnerability is not currently in the CISA KEV catalog, yet the potential impact—remote code execution, privilege escalation, and possible service disruption—demands urgent attention.
OpenCVE Enrichment