VulnCity

Cisco ISE Malicious File Upload

  • شناسه CVE: CVE-2025-20282
  • شدت: بحرانی
  • امتیاز CVSS: 9.1
  • فروشنده/سازنده: Cisco
File UploadCisco ISERCEMalicious File
A critical file upload vulnerability in Cisco ISE that allows an authenticated attacker to upload and execute arbitrary files, leading to remote code execution with elevated privileges.

## Vulnerability Overview
The vulnerability exists in the file upload functionality of the Cisco ISE web management interface. An attacker with valid low-privilege credentials can upload a specially crafted file that bypasses the file type validation checks, and then execute it to gain root-level access.

## Technical Details
- **Type:** Unrestricted File Upload (CWE-434)
- **Root Cause:** The file upload endpoint validates file extensions on the client side but fails to properly validate the file content and MIME type on the server side. Additionally, uploaded files are stored in a web-accessible directory.
- **Authentication:** Requires valid ISE credentials (any role)
- **Exploitation:** Upload a JSP webshell disguised as a legitimate file type, then access it via the web server.

## Impact
- Remote code execution with ISE application privileges
- Privilege escalation to root via known ISE local escalation paths
- Persistent backdoor through webshell

نرم‌افزارهای تحت تأثیر

  • Cisco ISE (Identity Services Engine)