Cisco Identity Services Engine
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*, +2 more
- <= 3.1
- 3.2
- 3.3
A vulnerability exists in the Cisco Identity Services Engine (ISE) GUI, allowing authenticated, remote attackers with administrative privileges to upload files to affected devices. This issue arises from improper validation in the file copy function. Exploitation of this vulnerability could enable the upload of arbitrary files to the system.
Successful exploitation allows for arbitrary file uploads to the affected system.
Cisco has released software updates to address this vulnerability. For information on which releases include the fix, consult the Cisco ISE advisory or the Cisco Security Advisories page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.