Cisco Identity Services Engine: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Medium · CISA Known Exploited Vulnerabilities ·
What happened
Cisco Identity Services Engine and ISE Passive Identity Connector have an exploited flaw allowing unauthenticated remote attackers to bypass the web management interface and gain unauthorized access.
What to do now
Apply Cisco mitigations/patches immediately; remove ISE management interfaces from the internet; restrict access to trusted admin networks; monitor for exploitation; if no fix, isolate or discontinue use per CISA BOD 26-04.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.