Unauthorized File Upload Vulnerability in Cisco Identity Services Engine
CVE-2025-20130

4.9MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
4 June 2025

Badges

👾 Exploit Exists

What is CVE-2025-20130?

A vulnerability exists in the API of Cisco Identity Services Engine (ISE) and the Passive Identity Connector (ISE-PIC) due to inadequate validation of file uploads. An authenticated remote attacker with administrative credentials could exploit this vulnerability by sending a specially crafted file upload request to a designated API endpoint. If successful, the attacker could upload arbitrary files to the affected device, potentially leading to further security compromises. It is crucial for users of Cisco ISE and ISE-PIC to take appropriate measures to mitigate this risk.

Affected Version(s)

Cisco Identity Services Engine Software 3.0.0

Cisco Identity Services Engine Software 3.0.0 p1

Cisco Identity Services Engine Software 3.0.0 p2

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20130 : Unauthorized File Upload Vulnerability in Cisco Identity Services Engine