Impact
The vulnerability in Cisco Secure Workload can be exploited to bypass existing authorization checks, allowing an attacker to access resources or perform actions beyond the granted permissions. This flaw is categorized as improper access control (CWE-284) and carries a CVSS score of 10, indicating that it could potentially provide complete system compromise if executed successfully.
Affected Systems
All deployments of Cisco Secure Workload are affected, regardless of version, because the vulnerability is present in the base software examined during the internal hardening release. No specific version bounds were provided in the advisory, so the impact applies universally to systems running Cisco Secure Workload.
Risk and Exploitability
The flaw is extremely severe, with a maximum CVSS score and no current EPSS data, meaning the exact likelihood of exploitation is uncertain but the potential damage is high. The vulnerability is not listed in the CISA KEV catalog, suggesting that known exploitation in the wild has not yet been observed. Attackers would most likely target the system remotely through legitimate or legitimate‑looking interfaces, taking advantage of missing permission checks to elevate privileges or read sensitive data.
OpenCVE Enrichment