Executive brief
Cisco Identity Services Engine (ISE) is a security policy management platform used to control access to corporate networks. A critical vulnerability allows an unauthenticated attacker to take full control of the system over the network. If exploited, an attacker could gain root-level access, allowing them to steal sensitive data, disrupt network operations, or bypass security controls entirely.
Technical details
An injection vulnerability (CWE-74) exists in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input. A remote, unauthenticated attacker can exploit this by sending a specially crafted API request to the affected device. Successful exploitation allows the attacker to execute arbitrary commands on the underlying operating system with root privileges. This vulnerability has been observed being exploited in the wild and carries a CVSS 3.1 score of 10.0. Affected versions include 3.3.0 and 3.4.0 (including various patch levels).
Affected products
- Cisco Identity Services Engine (ISE) 3.3.0, 3.4.0
- Cisco Identity Services Engine Passive Identity Connector (ISE-PIC) 3.3.0, 3.4.0
Timeline
- 2025-07-16: disclosed: Initial disclosure by Cisco
- 2025-07-28: kev added: Added to CISA Known Exploited Vulnerabilities catalog