Junglewise Threat Intelligence

CVE-2025-20281: Cisco Identity Services Engine unauthenticated RCE in API

CVE-2025-20281 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-07-28

Technologies: Cisco Identity Services Engine Passive Identity Connector, Cisco Identity Services Engine. Vendors: Cisco.

Executive brief

Cisco Identity Services Engine (ISE) is a security policy management platform used to control access to corporate networks. A critical vulnerability has been identified that allows an unauthorized person to take complete control of the system over the network. This could lead to a total service outage, theft of sensitive network credentials, or unauthorized access to the entire corporate network. This vulnerability is currently being exploited in the wild.

Technical details

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC (CWE-74) is caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can exploit this by sending a specially crafted API request to the affected device. Successful exploitation allows the attacker to execute arbitrary code on the underlying operating system with root privileges. This vulnerability has been observed in active exploitation and carries a CVSS score of 10.0. Cisco has released security updates to address this issue.

Affected products

  • Cisco Identity Services Engine (ISE) 3.3.0 (up to Patch 6), 3.4.0 (up to Patch 1)
  • Cisco Identity Services Engine Passive Identity Connector (ISE-PIC) 3.3.0 (up to Patch 6), 3.4.0 (up to Patch 1)

Timeline

  • 2025-07-24: other: Initial third-party reporting/blogging
  • 2025-07-28: advisory: Cisco advisory published
  • 2025-07-28: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-07-28: exploited: Confirmed active exploitation in the wild

Related threats