Cisco Identity Services Engine Arbitrary File Upload Vulnerability
TL;DR 📌
A medium-severity vulnerability has been identified in the Cisco Identity Services Engine (ISE) that allows authenticated attackers with administrative privileges to upload arbitrary files. No workarounds are available, and software updates have been released to address this issue.
What happened 🕵️♂️
A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability arises from improper validation of the file copy function, enabling attackers to exploit it by sending a crafted file upload through the Cisco ISE GUI. A successful exploit could lead to arbitrary file uploads on the affected system.
Affected products 🖥️
The vulnerability affects all versions of Cisco ISE, regardless of device configuration. Specifically, the following releases are impacted:
- Cisco ISE 3.1 and earlier
- Cisco ISE 3.2
- Cisco ISE 3.3
Cisco ISE 3.4 is not vulnerable.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 3.1 and earlier | 3.1 P10 | |
| 3.2 | 3.2 P7 | |
| 3.3 | 3.3 P3 | |
| 3.4 | Not vulnerable | |
| 1.1 | Clarified that the vulnerability occurs in the GUI. | |
| 1.0 | Initial public release. | |
| Cisco ISE | 3.1 P10 | 3.1 and earlier |
| Cisco ISE | 3.2 P7 | 3.2 |
| Cisco ISE | 3.3 P3 | 3.3 |
Workarounds 🧯
There are no workarounds that address this vulnerability.
Risk in context 🎯
The vulnerability has a CVSS score of 4.9, categorizing it as Medium severity. While the risk of exploitation is limited to authenticated users with administrative privileges, the potential for arbitrary file uploads poses a significant security risk. Organizations should prioritize updating their systems to mitigate this vulnerability.
Fast facts ⚡
- Vulnerability: Arbitrary File Upload in Cisco ISE
- CVSS Score: 4.9 (Medium)
- Exploitation: Requires authenticated administrative access
- Workarounds: None available
- Fixed Releases: Available for affected versions
For leadership 🧭
Executive summary. Cisco ISE, the network access control platform many organisations use to gate device and user access, has a GUI flaw letting an already-logged-in administrator upload arbitrary files to the appliance. There’s no workaround, so this needs scheduling into a patch cycle rather than fixing on the spot.
Why it matters:
- The bug lives in the ISE GUI’s file copy function, the same interface administrators use for routine day-to-day management of the platform.
- Every release line up to and including 3.3 is affected; only 3.4 is not vulnerable, so most deployed estates will need a patch.
- With no workaround published, the only mitigation is upgrading to the fixed patch release for your train.
- Arbitrary file upload on an ISE box is significant because ISE typically sits at the centre of network access control decisions, making the appliance itself a high-value target for anyone who already holds admin rights.
Now / Next / Later:
- Now: Identify every Cisco ISE deployment in your estate and check its version against the 3.1/3.2/3.3 fixed-release table to see which appliances need patching.
- Next: Schedule an upgrade to the first fixed release for your train (3.1 P10, 3.2 P7, or 3.3 P3) during your next maintenance window, since no workaround exists.
- Later: Tighten and audit who holds administrative accounts on ISE and how those accounts are provisioned, as part of routine review of privileged access to network control infrastructure.