Impact
A flaw in the REST API of Cisco ISE and Cisco ISE-PIC permits an authenticated attacker to inject malicious SQL in specific parameters that are used to build a database query. Exploitation requires valid administrative credentials and can lead to reading sensitive data from the monitoring database, thereby compromising confidentiality. The weakness originates from insufficient input validation before concatenation into an SQL statement and is classified as CWE‑89.
Affected Systems
The vulnerability impacts Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. Detailed affected versions are not provided in the advisory, so any deployed instance of these products should be treated as potentially vulnerable until a verified fix is deployed.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score below 1% suggests a low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Exploitation is feasible only over the network through the REST API using valid administrative credentials, meaning the attack surface is limited to authenticated users with administrative privileges.
OpenCVE Enrichment