File Upload Vulnerability in Cisco Identity Services Engine
CVE-2025-20131
What is CVE-2025-20131?
A vulnerability exists in the graphical user interface of Cisco Identity Services Engine (ISE), allowing authenticated remote attackers with administrative privileges to upload arbitrary files to the device. This issue arises from insufficient validation in the file copy function, making it possible for an attacker to exploit the system by sending a maliciously crafted file upload. If successfully executed, the attacker can compromise the integrity of the system by uploading unauthorized files.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved