Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px43-75mc-j6hq

Опубликовано: 04 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.

This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.

This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

EPSS

Процентиль: 13%
0.00044
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284
CWE-434

Связанные уязвимости

CVSS3: 4.9
nvd
8 месяцев назад

A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

CVSS3: 4.9
fstec
8 месяцев назад

Уязвимость компонента API платформы управления политиками соединений Cisco Identity Services Engine (ISE) и Cisco ISE Passive Identity Connector (ISE-PIC), позволяющая нарушителю загружать произвольные файлы

EPSS

Процентиль: 13%
0.00044
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284
CWE-434