Impact
A vulnerable API endpoint in Cisco Identity Services Engine allows an attacker to bypass authentication controls and gain administrative access to the web‑based management interface. The weakness is a failure to enforce authentication, identified by CWE‑648. Because the API accepts requests from unauthenticated sources, a remote attacker could craft a request that steals or escalates privileges. The resulting access is equivalent to that of a legitimate administrator, enabling configuration changes and monitoring that compromise confidentiality and integrity.
Affected Systems
Cisco Identity Services Engine software releases 3.1.0 through 3.5.0, including all intermediate patch milestones, and the Passive Identity Connector releases 3.1.0 through 3.5.0, are susceptible to authentication bypass via the affected API endpoints.
Risk and Exploitability
The CVSS score of 10 marks this flaw as critical, and the EPSS score of 14% indicates a relatively high likelihood of exploitation in the wild. The vulnerability is listed in CISA’s KEV catalog, underscoring its real‑world exploitation potential. The likely attack vector is remote: an unauthenticated client can send a crafted API request over the network to the vulnerable endpoint and bypass authentication, gaining privileged access.
OpenCVE Enrichment