Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +2 more
- <= 3.0
- >= 3.1, < 3.1 P10
- >= 3.2, < 3.2 P7
- >= 3.3, < 3.3 P3
A vulnerability exists in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), allowing authenticated, remote attackers with administrative privileges to upload files to affected devices. This issue arises from improper validation in the file copy function, enabling attackers to send crafted file upload requests to specific API endpoints. Exploitation of this vulnerability could result in the upload of arbitrary files to the system.
Successful exploitation allows for arbitrary file uploads to the affected system.
Users can upgrade to Cisco ISE versions 3.1 P10, 3.2 P7, or 3.3 P3. For Cisco ISE-PIC, migrate to a fixed release. Consult the Cisco Security Advisories page for guidance on software upgrades.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.