[CIVN-2025-0154] Arbitrary File Upload Vulnerability in Cisco Unified Intelligence Center
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Arbitrary File Upload Vulnerability in Cisco Unified Intelligence Center
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Cisco Unified Intelligence Center
Overview
A vulnerability has been reported in web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary files to an affected device.
Target Audience:
All IT administrators and individuals responsible for maintaining and updating Cisco Unified Intelligence Center.
Risk Assessment:
High risk of data manipulation and service disruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
This vulnerability exists due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by uploading arbitrary files to an affected device.
Successful exploitation of this vulnerability could allow the attacker to store malicious files on the system and execute arbitrary commands on the operating system.
Solution
Apply appropriate updates as mentioned in Cisco Advisory
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-file-upload-UhNEtStm
Vendor Information
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-file-upload-UhNEtStm
References
CISCO
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-file-upload-UhNEtStm
CVE Name
CVE-2025-20274
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmiDlM8ACgkQ3jCgcSdc
ys+SRQ/7BR9TOFdgOr4i78+trqV4aMGsGp+ZD+f/7qKSpodKWwIxBlNzcc72CLdE
3gSFcF1uEYdfKKabUQIqXiAMiqyyJCZVo/QnO3i7tS6m2WO87lneBT3kVCjtAei0
QqqqBGUlNdu+oRnXhgadCdbZo9UilTfiAuuPzd9al4FDQNrPwkrzqrTvadZuO9oS
GIy4yghDLrTcDQ0XxF6NZUioOhSUUxYrZxhe23PMq61+OJRirxVNPcEHkvegrUFo
UQGJCG4KP4SNleMWvAnSKPfYSnVj4Zjiv57hsO9iikvHCZyBlMSd+Al21Rr1sWbr
AGkm+51yZJWp4ZvYE/0pPCtky5G1H1ljafsekccu+7EJH0T5s7NT71WSR+v0e3rP
DCQqzSRQtWZTFznvj866W4Jp56hJSFssQFJIsTYSSyaozG4Tq8KVZ9p9pugiI96n
tNKnd08lm1OoyCkqI1ahkRrlmlZNAVNyvt5a+CLNrT15lELF1fDPtr3KsgP1Qd8Y
togOuzmqjw54eD/grlr7z0Bgj9U1i8ffd/6vmVrFwNNR8COaIeodu+la2MWpC2Wo
5KDgWBE02IT2SEMu1Em0ya8tT4LWzfNteZ+E9mb7/+XdgXjSzzbZNO0wABlUMXKp
nFt/aVyQz8+9rZPoaIQTnXqBBgMj+utl3QsryIOxogjfHwkkdBA=
=ZUJt
—–END PGP SIGNATURE—–