File Upload Vulnerability in Cisco Identity Services Engine (ISE)
CVE-2023-20195
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 1 November 2023
Summary
Two vulnerabilities exist within Cisco's Identity Services Engine (ISE) that could permit an authenticated remote attacker to upload arbitrary files to the device. These security flaws arise from insufficient validation of file uploads through the web-based management interface. An attacker possessing valid Administrator credentials can exploit these vulnerabilities to upload specially crafted files, potentially allowing for the storage of malicious files in designated directories. This exploitation could lead to further attacks, including executing arbitrary code on the affected device with root privileges.
Affected Version(s)
Cisco Identity Services Engine Software 2.6.0
Cisco Identity Services Engine Software 2.6.0 p1
Cisco Identity Services Engine Software 2.6.0 p2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved