Impact
The flaw resides in the client provisioning download feature of Cisco ISE and ISE‑PIC, where the software fails to validate path traversal sequences provided by a user. As a result, an attacker who can send a crafted HTTP request to the provisioning download service can read arbitrary files on the device without authentication. This capability can expose protected configuration or credential data, compromising the confidentiality of the system.
Affected Systems
The vulnerability affects Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. No specific version ranges were disclosed in the advisory, so any installed instance that has not applied the vendor’s update is considered affected.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity. The EPSS score is below 1%, suggesting exploitation is currently unlikely in the wild, and the issue is not listed in CISA’s KEV catalog. Because the attack requires no authentication and can be performed remotely over the provisioning endpoint, an attacker can easily obtain sensitive files if the service is exposed to potential adversaries. Consequently, organizations should regard this as a moderate‑to‑high risk if provisioning traffic is accessible from untrusted networks.
OpenCVE Enrichment