Impact
A vulnerability exists in the API of Cisco Identity Services Engine and its Passive Identity Connector that allows an authenticated, remote attacker to read files on the underlying operating system. The flaw stems from an improper restriction of XML external entity references, enabling an attacker to craft a request that resolves an external entity reference to local files the process can access. In a successful exploit, the attacker can read arbitrary files with the rights of the affected process, potentially exposing credentials, configuration data, or other sensitive information.
Affected Systems
The affected products are Cisco ISE, including the Passive Identity Connector component. The vulnerability applies to all current releases of these products that have not yet applied the Cisco-published fix listed in the referenced advisory.
Risk and Exploitability
The CVSS base score of 4.9 indicates a moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Because an attacker must be authenticated to the system and able to send crafted API requests, the attack surface is limited to users who already possess valid credentials. Nonetheless, once authenticated, the attacker can read any file the process has permission to read, which could lead to significant information disclosure.
OpenCVE Enrichment