Impact
The vulnerability arises from the offline profiler feed service’s XML parser not disabling external entity resolution. An attacker who has valid administrative credentials can upload a crafted offline feed package through the administrative interface. If the upload succeeds, the service parses the feed metadata and resolves external entity references, enabling the attacker to read arbitrary files from the device’s file system and issue requests to internal systems. This gives the attacker the ability to exfiltrate sensitive files and potentially use the device as a pivot point for further internal network activity.
Affected Systems
The affected products are Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. Specific release versions are not enumerated in the advisory, so any installation of the documented products that has not been updated with the security release may be vulnerable.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity, while an EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog, suggesting that no widespread public exploits are known. Because the attack requires authenticated administrative access, the risk is limited to environments where such credentials are available. Nonetheless, the potential for read‑of‑arbitrary files and internal request execution makes the impact significant for protecting confidential data.
OpenCVE Enrichment