NA

CVE-2023-20272

Published: 21/11/2023 Updated: 25/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote malicious user to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. An attacker could exploit this vulnerability by uploading a malicious file to the web interface. A successful exploit could allow the malicious user to replace files and gain access to sensitive server-side information.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity services engine 3.0.0

cisco identity services engine 3.1

Vendor Advisories

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to upload malicious files to the web root of the application or conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device To exploit these vulnerabilities, an attacker must have ...