Unauthorized File Upload Vulnerability in Cisco Identity Services Engine
CVE-2025-20130
4.9MEDIUM
What is CVE-2025-20130?
A vulnerability exists in the API of Cisco Identity Services Engine (ISE) and the Passive Identity Connector (ISE-PIC) due to inadequate validation of file uploads. An authenticated remote attacker with administrative credentials could exploit this vulnerability by sending a specially crafted file upload request to a designated API endpoint. If successful, the attacker could upload arbitrary files to the affected device, potentially leading to further security compromises. It is crucial for users of Cisco ISE and ISE-PIC to take appropriate measures to mitigate this risk.
Affected Version(s)
Cisco Identity Services Engine Software 3.0.0
Cisco Identity Services Engine Software 3.0.0 p1
Cisco Identity Services Engine Software 3.0.0 p2