Cisco Identity Services Engine (cisco-sa-ise-unauth-rce-ZAd2GnJ6)

critical Nessus Plugin ID 240417

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco ISE is affected by a vulnerability.

- A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system. (CVE-2025-20282)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug IDs CSCwo99449, CSCwp02821

See Also

http://www.nessus.org/u?c8410918

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwo99449

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwp02821

Plugin Details

Severity: Critical

ID: 240417

File Name: cisco-sa-ise-unauth-rce-ZAd2GnJ6_CVE-2025-20282.nasl

Version: 1.1

Type: local

Family: CISCO

Published: 6/25/2025

Updated: 6/25/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.3

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-20282

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine_software

Required KB Items: Host/Cisco/ISE/version

Exploit Ease: No known exploits are available

Patch Publication Date: 6/25/2025

Vulnerability Publication Date: 6/25/2025

Reference Information

CVE: CVE-2025-20282