Impact
A user‑supplied path in the certificate import feature of Cisco ISE’s web management interface is insufficiently validated, allowing an authenticated attacker with administrative access to retrieve any file on the device. The vulnerability can expose sensitive data such as configuration files or credentials. The weakness matches CWE‑22, indicating insecure file path handling.
Affected Systems
The affected products are Cisco Identity Services Engine and Cisco ISE Passive Identity Connector. No specific version information is provided in the advisory, so all releases of these products remain potentially vulnerable until patched.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% shows a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Since exploitation requires valid administrative credentials, the risk is confined to environments where such privileges are granted; a successful exploit would allow attackers to read arbitrary files, potentially compromising confidential information.
OpenCVE Enrichment