Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-20131

Опубликовано: 20 авг. 2025
Источник: nvd
CVSS3: 4.9
EPSS Низкий

Описание

A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.

This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload using the Cisco ISE GUI. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

EPSS

Процентиль: 9%
0.00031
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.9
github
6 месяцев назад

A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload via the ISE GUI. A successful exploit could allow the attacker to upload arbitrary files to an affected system.

CVSS3: 4.9
fstec
6 месяцев назад

Уязвимость функции копирования файлов графического интерфейса платформы управления политиками соединений Cisco Identity Services Engine, позволяющая нарушителю загрузить произвольные файлы

EPSS

Процентиль: 9%
0.00031
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-284