File Upload Vulnerability in Cisco Identity Services Engine
CVE-2025-20131

4.9MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
20 August 2025

Badges

👾 Exploit Exists

What is CVE-2025-20131?

A vulnerability exists in the graphical user interface of Cisco Identity Services Engine (ISE), allowing authenticated remote attackers with administrative privileges to upload arbitrary files to the device. This issue arises from insufficient validation in the file copy function, making it possible for an attacker to exploit the system by sending a maliciously crafted file upload. If successfully executed, the attacker can compromise the integrity of the system by uploading unauthorized files.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20131 : File Upload Vulnerability in Cisco Identity Services Engine