Impact
This vulnerability arises from insufficient validation of user‑supplied input to the APIs used by Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE‑PIC), enabling an authenticated remote attacker to inject SQL or HQL queries. Successful exploitation can lead to reading or modifying data that the attacker is not authorized to access, resulting in a confidentiality and integrity breach. The attack requires valid administrative credentials.
Affected Systems
Affected products are Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE‑PIC) as identified by the CNA. The advisory does not list specific versions, so all releases of these products prior to the published fix are considered vulnerable.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% reflects a low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Because only authenticated attackers can exploit it, the threat is primarily internal or from compromised administrative credentials. Nonetheless, the potential to compromise sensitive data warrants prompt remediation.
OpenCVE Enrichment