Impact
A flaw in the REST API of Cisco ISE and Cisco ISE‑PIC lets an unauthenticated attacker send a crafted HTTP request to the exposed API port and bypass authentication checks. Successful exploitation grants the attacker full administrative control, enabling read and modification of the ISE configuration and identity data. The vulnerability carries a CVSS score of 10, indicating a critical impact if exploited.
Affected Systems
The affected products are Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. No specific version information is provided in the advisory, so all released versions remain potentially vulnerable until a patched version is deployed.
Risk and Exploitability
The EPSS score of less than 1% suggests that no widespread exploitation is currently observed, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high severity, coupled with the attacker’s ability to leverage simple HTTP requests without prior authentication, creates a substantial risk for any environment exposing the REST API to external networks. If the API port is reachable, an attacker could immediately gain administrative privileges.
OpenCVE Enrichment