build1 publisher
A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API
Cisco disclosed an unauthenticated authorization bypass in the Identity Services Engine REST API on 16 September. Because the request never presents a credential, it leaves just one trace: a privileged API call that succeeded.
Publishers:dev.to
Reality
- Evidence55
- Adoption20
- Hype gap−10
- Incentives40
- Confidence52