Cisco Identity Services Engine Path Traversal Vulnerability

MonitorCVSS 5.5cisco-sa-ise-traversal-xNt7wb2YJul 15, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

A path traversal vulnerability in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector allows an authenticated administrator to read or delete arbitrary files on the affected system due to improper validation of user-supplied input in HTTP requests. An attacker with valid administrative credentials could exploit this by sending a crafted HTTP request to access sensitive files, authentication databases, or delete critical system files.

What this means
What could happen
An attacker with admin credentials could read or delete arbitrary files on your ISE system, potentially including authentication databases, configuration files, or operational records critical to network access control.
Who's at risk
Network administrators and security teams relying on Cisco Identity Services Engine for authentication and authorization should prioritize this vulnerability. ISE is typically used to centralize network access control, 802.1X authentication, and device profiling across enterprise networks, including utilities and critical infrastructure. The ISE Passive Identity Connector extends monitoring to passive segments. Any organization using ISE in their AAA (authentication, authorization, and accounting) infrastructure is affected.
How it could be exploited
An attacker with valid ISE administrative credentials crafts an HTTP request containing path traversal sequences (e.g., ../) and sends it to the ISE web interface. The system fails to validate the input and allows the attacker to navigate the file system to read or delete files outside the intended application directory.
Prerequisites
  • Valid ISE administrative credentials
  • Network access to the ISE web interface (typically port 443)
  • ISE system accessible from attacker's network position
Requires valid administrative credentials (insider risk)Remotely exploitable via web interfaceNo authentication bypass needed (admin credentials already required)Access to sensitive authentication and configuration dataPotential for operational disruption through file deletion
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Identity Services Engine SoftwareAll versionsFix available
ISE Passive Identity ConnectorAll versionsFix available
Remediation & Mitigation
0/5
Do now
0/2
WORKAROUNDRestrict network access to the ISE web interface (port 443) to only authorized administrative workstations and networks
WORKAROUNDReview ISE administrative access logs for suspicious HTTP requests containing path traversal patterns (e.g., requests with '../' or encoded equivalents)
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

ISE Passive Identity Connector
HOTFIXUpdate Cisco ISE Passive Identity Connector to the patched version
All products
HOTFIXUpdate Cisco ISE to the patched version released by Cisco
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate ISE management interfaces from untrusted networks
API: /api/v1/advisories/7fd0b84c-5542-4fc4-a248-5f0f85722772

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Cisco Identity Services Engine Path Traversal Vulnerability | CVSS 5.5 - OTPulse