Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px43-75mc-j6hq

Опубликовано: 04 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.

This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.

This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

EPSS

Процентиль: 42%
0.00508
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284
CWE-434

Связанные уязвимости

CVSS3: 4.9
nvd
больше 1 года назад

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

CVSS3: 4.9
fstec
больше 1 года назад

Уязвимость прикладного программного интерфейса платформы управления политиками соединений Cisco Identity Services Engine (ISE) и виртуального устройства сбора данных об аутентификации пользователей Cisco ISE Passive Identity Connector (ISE-PIC), позволяющая нарушителю загружать произвольные файлы

EPSS

Процентиль: 42%
0.00508
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284
CWE-434