cisco-sa-ise-file-upload-P4M8vwXY: Cisco Identity Services Engine Arbitrary File Upload Vulnerability
A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint. A successful exploit could allow the attacker to upload arbitrary files to an affected system.Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-file-upload-P4M8vwXY
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-ise-file-upload-P4M8vwXY?
The severity of cisco-sa-ise-file-upload-P4M8vwXY is high due to the potential for unauthorized file uploads by authenticated users.
How do I fix cisco-sa-ise-file-upload-P4M8vwXY?
To fix cisco-sa-ise-file-upload-P4M8vwXY, apply the appropriate software updates and patches recommended by Cisco.
Who is affected by cisco-sa-ise-file-upload-P4M8vwXY?
Cisco Identity Services Engine and Cisco ISE Passive Identity Connector users with administrative privileges are affected by cisco-sa-ise-file-upload-P4M8vwXY.
What is the impact of cisco-sa-ise-file-upload-P4M8vwXY?
The impact of cisco-sa-ise-file-upload-P4M8vwXY includes the potential for unauthorized access and manipulation of files on affected devices.
What causes the cisco-sa-ise-file-upload-P4M8vwXY vulnerability?
The cisco-sa-ise-file-upload-P4M8vwXY vulnerability is caused by improper validation of file uploads in the API of Cisco Identity Services Engine.