Impact
A directory traversal flaw in Cisco ISE’s web‑based file management function lets an attacker with valid administrative credentials send crafted requests that cause the underlying operating system to delete arbitrary files or directories. The flaw allows complete removal of any file within the file system space exposed by the ISE service, potentially compromising availability, data integrity, and confidentiality of the managed device.
Affected Systems
The weakness affects Cisco Identity Services Engine Software and the Cisco ISE Passive Identity Connector. Specific version information is not disclosed in the advisory, so all deployments of these products that rely on the web‑based management interface are considered vulnerable.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score of 1 % reflects a low‑to‑moderate probability of exploitation. The vulnerability is exploitable only against authenticated users with administrative privileges, but once such access is obtained, an attacker can delete any file reachable from the web interface. The issue is not listed in the CISA KEV catalog, but its remote nature and need for admin credentials still pose a significant risk for environments where management access is broadly available.
OpenCVE Enrichment