AI analysis
Cisco ISE contains an XML external entity (XXE) injection flaw (CWE-611) in its offline profiler feed service, caused by parsing attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An authenticated remote attacker with valid administrative credentials can exploit it by uploading a crafted offline feed package through the administrative interface. Successful exploitation allows the attacker to read arbitrary files from the device's file system and issue requests to internal systems from the ISE appliance (server-side request forgery), though confidentiality-only impact gives it a medium CVSS 4.9. All organizations running Cisco ISE are potentially affected, but exploitation requires administrative access to the management interface, which is typically restricted to internal management networks. No public proof-of-concept or confirmed exploitation of this specific flaw is known, although Cisco has separately warned that another ISE zero-day (an auth bypass rated CVSS 10.0) is being actively exploited, so ISE deployments are currently under attacker attention.
What to do: Upgrade ISE to the fixed release identified in the Cisco security advisory once published, as no fixed version is listed in the available data. Restrict access to the ISE administrative interface to trusted management networks and review logs for unexpected offline feed package uploads or outbound requests originating from ISE appliances. Given that a separate, actively exploited ISE zero-day (CVSS 10.0 auth bypass) has been announced, treat ISE patching as an urgent priority and verify all ISE nodes in the deployment are updated.
Affected
| Cisco Identity Services Engine (ISE) - offline profiler feed service | — |
Estimated exposure
largetens of thousands of enterprise deployments worldwide, with likely only a small fraction (low thousands or fewer) of admin interfaces internet-exposed — Cisco ISE is the dominant enterprise NAC/identity platform with a large installed base across enterprises, universities, and government, but the vulnerable administrative interface is usually deployed on internal management networks,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.