Impact
The flaw in the guest portal web application of Cisco Identity Services Engine allows an unauthenticated, remote attacker to send forged posture status events into the pipeline. This insufficient authentication on an internal interface can cause the system to accept and store fabricated posture information, potentially leading to an attacker appearing to have a healthy endpoint when they do not. The primary impact is the ability to alter endpoint posture data, which can affect network access policies and the integrity of postural assessment processes.
Affected Systems
Affected products include Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. The specific versions impacted are not disclosed in the advisory; administrators should verify whether their deployment corresponds to the described vulnerability by checking the vulnerability description against their installed release. No granular version list is provided.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploits. Exploitation requires sending a crafted request to the exposed internal interface via the guest portal; no additional prerequisites, such as privileged access, are mentioned. Because the interface accepts forged data without authentication, the attacker can remotely manipulate posture status without logging in.
OpenCVE Enrichment