Impact
A SQL injection flaw exists in the APIs of Cisco Identity Services Engine software. Insufficient validation of certain request parameters that are concatenated directly into an SQL query allows an authenticated attacker to inject malicious SQL. A successful exploit can read arbitrary database content and also enable server‑side request forgery against internal targets.
Affected Systems
Cisco Identity Services Engine Software. No specific affected version ranges are listed in this advisory; any deployed instance of ISE that is not yet patched may be vulnerable.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity. However, the EPSS score of less than 1% suggests that exploitation is expected to be rare at present. The vulnerability is not listed in CISA’s KEV catalog, and requires that the attacker possess valid administrative credentials to reach the vulnerable API. Thus, while the impact is severe if exploited, the attack vector is limited to authenticated users with administrative privileges, and the overall risk is moderate‑high.
OpenCVE Enrichment