A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.
History

Wed, 04 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Jun 2025 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.
Title Cisco Identity Services Engine Access Control Bypass Vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2025-06-04T16:17:27.311Z

Updated: 2025-06-23T20:27:53.961Z

Reserved: 2024-10-10T19:15:13.212Z

Link: CVE-2025-20130

cve-icon Vulnrichment

Updated: 2025-06-04T18:13:26.585Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-04T17:15:25.833

Modified: 2025-06-05T20:12:23.777

Link: CVE-2025-20130

cve-icon Redhat

No data.