File Upload Vulnerability in Cisco Identity Services Engine (ISE)
CVE-2023-20195

7.2HIGH

Key Information:

Vendor
Cisco
Vendor
CVE Published:
1 November 2023

Summary

Two vulnerabilities exist within Cisco's Identity Services Engine (ISE) that could permit an authenticated remote attacker to upload arbitrary files to the device. These security flaws arise from insufficient validation of file uploads through the web-based management interface. An attacker possessing valid Administrator credentials can exploit these vulnerabilities to upload specially crafted files, potentially allowing for the storage of malicious files in designated directories. This exploitation could lead to further attacks, including executing arbitrary code on the affected device with root privileges.

Affected Version(s)

Cisco Identity Services Engine Software 2.6.0

Cisco Identity Services Engine Software 2.6.0 p1

Cisco Identity Services Engine Software 2.6.0 p2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.