CyberRota Analysis
AI-GeneratedA vulnerability in the API of Cisco ISE and Cisco ISE-PIC allows authenticated remote attackers to exploit improper restrictions on XML external entity references, potentially enabling them to read sensitive files from the underlying operating system. The impact includes unauthorized access to file data, which could lead to further exploitation or data leakage. Organizations using affected Cisco products should prioritize remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system of an affected device. This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read specific files on the affected system that the underlying process has permission to access.
Related CVEs
Other vulnerabilities affecting the same vendor(s)