THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-20131 (MEDIUM 4.9) — A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could

[NVD] CVE-2025-20131 (MEDIUM 4.9) — A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability is due to improper validation of the file copy function. An attacker could

lownvdPublished 2025-08-20

CVE-2025-20131 CVSS: 4.9 MEDIUM Published: 2025-08-20T17:15:34.413

A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device.

This vulnerability is due to improper validation of the file copy function. An attacker could exploit this vulnerability by sending a crafted file

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-20131