Impact
The vulnerability allows an authenticated remote attacker to inject arbitrary SQL into the REST API payloads of Cisco ISE and Cisco ISE-PIC. Certain parameters are concatenated directly into SQL clauses without parameterization, enabling the attacker to craft requests that contain malicious SQL statements. A successful exploitation could read sensitive information from the session database. The weakness is identified as CWE-89.
Affected Systems
Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software are affected. No specific version information is provided in the advisory; any installation of these products that exposes the vulnerable REST endpoints is potentially susceptible.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Because the attacker must possess valid administrative credentials, the attack requires remote access and privileged credentials. If these conditions are met, the attacker can retrieve session information, compromising confidentiality of user sessions and potentially aiding further lateral movement.
OpenCVE Enrichment