CyberzSOC

Publication detail
← Back to advisories & guidance

2025-025: Critical Vulnerabilities in Cisco ISE ↗ source

July 18, 2025 CERT-EU Advisory

Summary

It is recommended updating affected product as soon as possible. The vulnerabilities CVE-2025-20281 and CVE-2025-20337, both with a CVSS score of 10, are due to insufficient validation of user-supplied input in a specific API endpoint of the product. An attacker could exploit these vulnerabilities by submitting a crafted API request. A successful exploit could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The vulnerability CVE-2025-20282, with a CVSS score of 10, is due to a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-20281 10.0 Critical Cisco Identity Services Engine Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of…
CVE-2025-20282 10.0 Critical Cisco Cisco Identity Services Engine Software A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff…
CVE-2025-20337 10.0 Critical Cisco Identity Services Engine Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.