Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kentaro Kwane

Researcher fromGMO Cybersecurity by Ierae
#40504of 56,330
7.2Total CVSS
Vulnerabilities · 1
PT-2025-23818
7.2
2025-06-04
Cisco · Cisco Ise Passive Identity Connector · CVE-2025-20130
**Name of the Vulnerable Software and Affected Versions** Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) (affected versions not specified) **Description** A vulnerability in the API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file upload request to a specific API endpoint, such as "/api/v1/upload". A successful exploit could allow the attacker to upload arbitrary files to an affected system. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.