Cisco ISE和Cisco ISE-PIC都是美国思科(Cisco)公司的产品。Cisco ISE是一个 NAC 解决方案。用于管理零信任架构中的端点、用户和设备对网络资源的访问。Cisco ISE-PIC是一个组件。 Cisco ISE和Cisco ISE-PIC存在安全漏洞,该漏洞源于文件验证不足,可能导致上传和执行任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Identity Services Engine Software | 3.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Proof of concept of CVE-2025-20282, the perfect 10. | https://github.com/skadevare/CiscoISE-CVE-2025-20282-POC | POC Details |
| 2 | Cisco ISE and Cisco ISE-PIC contain an unrestricted file upload vulnerability caused by lack of file validation in an internal API, letting unauthenticated remote attackers upload and execute files as root, exploit requires crafted file upload. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-20282.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-20281 | 10.0 CRITICAL | Cisco ISE API Unauthenticated Remote Code Execution Vulnerability |
| CVE-2025-20264 | 6.4 MEDIUM | Cisco Identity Services Engine Authorization Bypass Vulnerability |
No comments yet