Cisco ISE Zero-Day Exploited, Critical Vulnerability Patched
Cisco's Identity Services Engine (ISE) and ISE Passive Identity Connector have been hit by a critical zero-day vulnerability, confirmed to be actively exploited by attackers.
The unauthenticated API flaw affects products regardless of configuration, with a CVSS score of 10.0, allowing an attacker to gain command execution with root privileges.
Cisco has released fixed destinations for the affected products: ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4.
However, these patches cannot establish whether an attacker previously obtained root access or concealed evidence on an exposed node.