Impact
A vulnerable API endpoint in Cisco Identity Services Engine and its passive connector allows an attacker who has valid administrative credentials to inject SQL or HQL statements. The insufficient input validation can lead to the execution of arbitrary database queries, potentially exposing sensitive information or altering configuration data that should be protected. The flaw is identified as CWE‑89, reflecting classic injection weakness.
Affected Systems
The vulnerability affects Cisco ISE Passive Identity Connector and Cisco Identity Services Engine Software. Any deployment of these products that has not yet applied Cisco’s latest security update is susceptible. No specific version range is listed, so all released iterations could be impacted until mitigated.
Risk and Exploitability
The CVSS score of 4.9 places this advisory in the medium range, but the EPSS score of less than 1 % indicates a very low likelihood of this vulnerability being actively exploited at present. It is not listed in the CISA KEV catalog. Exploitation requires remote authenticated access, meaning that an attacker would need administrative credentials or a credential compromise to deliver a malicious payload. The potential impact is limited to confidentiality and integrity of data within the database, not system availability.
OpenCVE Enrichment