ZeroHour

CVE-2025-20281

KEV PoC large

Unauthenticated Root RCE via API Injection in Cisco ISE and ISE-PIC

CISA: Cisco Identity Services Engine Injection Vulnerability

CVSS 3.1
10.0 critical
EPSS
97%p100
Published
()
KEV added
AI analysis

CVE-2025-20281 is an injection flaw (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to that API; no valid credentials or user interaction are required. A successful exploit yields arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device (scope-changing per the CVSS 10.0 score). Any organization running affected ISE or ISE-PIC releases is exposed, particularly where the vulnerable API is reachable from untrusted networks. The flaw is confirmed under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-28, EPSS assigns a 97.1% probability of exploitation within 30 days, and ZDI has published a writeup of the unauthenticated root RCE.

What to do: Upgrade Cisco ISE and ISE-PIC to the patched releases specified in Cisco's PSIRT advisory, and check whether the vulnerable API/admin interface is reachable from untrusted networks, restricting access until patching is complete. As a KEV entry added 2025-07-28, U.S. federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product; given EPSS of 97.1% and confirmed active exploitation, prioritize internet-facing ISE instances and review API/web-server logs for signs of exploitation.

Affected
Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
Estimated exposure
largeroughly tens of thousands of enterprise/government deployments worldwide (estimate), with an unknown subset exposing the vulnerable API to untrusted networks — Cisco ISE is a widely deployed enterprise network access control and identity platform, but no public install-base counts or internet-exposure scan data were included in the source data, so this is an order-of-magnitude estimate only.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CISA Known Exploited Vulnerability
Affected
Cisco Identity Services Engine
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
identity services engine, identity services engine passive identity connector
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news