CyberRota Analysis
AI-GeneratedThe vulnerability affects the Online Certificate Status Protocol (OCSP) responder in Cisco Identity Services Engine (ISE) and Cisco ISE-PIC, allowing unauthenticated remote attackers to send crafted requests that trigger an administrative reload of the OCSP responder's certificate and key material. This could disrupt the certificate validation process, potentially leading to service outages or unauthorized access. Organizations using these Cisco products should prioritize addressing this vulnerability to maintain the integrity of their certificate management systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause the OCSP responder to reload certificate and key material on demand.
Related CVEs
Other vulnerabilities affecting the same vendor(s)