CVE-2025-20131: Cisco Identity Services Engine Arbitrary File Upload Vulnerability
A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload using the Cisco ISE GUI. A successful exploit could allow the attacker to upload arbitrary files to an affected system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20131?
CVE-2025-20131 is rated as a high severity vulnerability due to its potential impact on system integrity.
How do I fix CVE-2025-20131?
To fix CVE-2025-20131, it is recommended to apply the latest security patches provided by Cisco for the Identity Services Engine.
Who is affected by CVE-2025-20131?
CVE-2025-20131 affects users of Cisco Identity Services Engine with administrative access.
What are the potential consequences of CVE-2025-20131?
The potential consequences of CVE-2025-20131 include unauthorized file uploads, which could lead to data manipulation or system compromise.
Is user authentication required to exploit CVE-2025-20131?
Yes, CVE-2025-20131 requires an attacker to have valid credentials and administrative privileges for exploitation.