What happened
A vulnerability has been identified in the SXP REST API component of Cisco Identity Services Engine (ISE). The issue stems from insufficient validation of user-supplied input, which enables an authenticated attacker to perform SQL injection attacks. Successful exploits may result in unauthorized viewing or modification of data within the device’s underlying database. Additionally, in single-node deployments, exploitation could lead to a denial of service (DoS) condition, rendering the affected node unavailable and preventing access for endpoints that have not yet authenticated. Exploitation requires the attacker to have valid administrative credentials, the SXP service to be enabled, and at least one SXP connection configured on the affected device. The vulnerability can be exploited remotely through an exposed service without user interaction, making it a critical security concern.
Who is affected
Organizations operating Cisco ISE deployments with enabled SXP services are potentially impacted. Affected environments include those where the SXP REST API is accessible over the network. Since remote attack vectors are possible without requiring user action, any organisation with such configurations should consider their environment vulnerable to this vulnerability, provided the attacker has the necessary authenticated access and the SXP service enabled.
Recommended actions
- Implement network segmentation and access controls to restrict external and unauthorised network access to the affected service, reducing the attack surface for exploitation.
- Review and enforce strict credential management policies to prevent unauthorised use of administrative accounts with high privileges on Cisco ISE devices.
- Monitor network traffic for indications of exploitation attempts targeting the exposed SXP REST API endpoints.
- Apply available security updates or patches as soon as they become available, following vendor guidance and security advisories.
- Disable or restrict the use of the SXP REST API where possible until a patch or workaround is released.
Indicators of compromise
No specific indicators of compromise are currently available at this time.

