Impact
A missing authentication check in the OCSP responder of Cisco ISE and its Passive Identity Connector allows an unauthenticated, remote attacker to trigger a reload of the responder’s certificate and key material. An attacker can send a crafted request to an exposed OCSP endpoint, causing the responder to drop its current keys and certificates and reload new ones on demand. The resulting transient loss of OCSP functionality can interrupt certificate validation flows and potentially disrupt authentication and authorization services that rely on the ISE appliance, leading to a denial‑of‑service effect for users and devices that depend on the ISE infrastructure.
Affected Systems
The vulnerability affects Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. No specific affected versions are listed in the CNA data; therefore, any installation of the product that includes the vulnerable OCSP responder component is potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low probability that the vulnerability will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw without authentication by sending a crafted request to the OCSP endpoint from outside the network. Because the exploit consists of a simple HTTP-like request, the attack can be launched remotely against any exposed ISE instance that has the vulnerable OCSP responder enabled.
OpenCVE Enrichment