Impact
A flaw in the Cisco ISE REST API allows an authenticated remote attacker who has valid administrative credentials to upload files with crafted paths. This attack can place files in arbitrary locations and execute commands as root, effectively compromising the entire device. The likely attack vector is via the REST API exposed over the management network, though the advisory does not explicitly state the network transport.
Affected Systems
The affected product is Cisco Identity Services Engine Software from Cisco. No specific version numbers are listed in the advisory, so the vulnerability may exist in all versions prior to any patch that Cisco issues.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated administrative access, which limits the threat to privileged users or those who have compromised credentials. Once authenticated, an attacker can upload malicious files and run arbitrary commands as root, resulting in full system compromise.
OpenCVE Enrichment