Impact
The flaw allows an authenticated administrator to upload a file with a crafted path containing directory traversal characters, enabling the operator to write a file to an arbitrary location on the device. This could alter configuration files, inject malicious code, or otherwise compromise the system’s integrity and availability.
Affected Systems
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE‑PIC). No version ranges are listed in the advisory, so the issue potentially applies to all releases that contain the affected web‑based management interface.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate impact, and the EPSS score of less than 1% shows a very low likelihood of exploitation based on current data. The vulnerability is not included in the CISA KEV catalog. Because the attacker must be authenticated and possess administrative privileges, the attack vector is remote via the web interface of the affected product. With those preconditions met, the attacker could overwrite critical files and elevate their control over the system.
OpenCVE Enrichment