Impact
A flaw in Cisco Identity Services Engine (ISE) and its Passive Identity Connector allows an attacker who can authenticate with administrative credentials to craft malicious input to ISE APIs. The input is concatenated into database queries without proper validation, giving the attacker the ability to execute arbitrary SQL or HQL commands. This could expose sensitive configuration or user data, or alter data that the attacker should not manipulate, thereby breaching confidentiality and integrity of the system.
Affected Systems
The vulnerability affects Cisco ISE and the Cisco ISE Passive Identity Connector. No specific affected version ranges are listed in the CNA data, so any deployment of these products is potentially vulnerable until a patch is applied or mitigated.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity, and the EPSS score of less than 1 % suggests a low likelihood of exploitation. Because an attacker must hold valid administrative credentials, the attack requires insider or compromised credentials; however, the use of this flaw could lead to significant data exposure or modification if such credentials are in use. The vulnerability is not included in the CISA KEV catalog, indicating no publicly known large‑scale exploitation at the time of reporting.
OpenCVE Enrichment