ZeroHour

CVE-2025-20282

large

Unauthenticated File-Upload RCE with Root Privileges in Cisco ISE and ISE-PIC

CVSS 3.1
10.0 critical
EPSS
27%p98
Published
()
Modified
AI analysis

CVE-2025-20282 is a critical (CVSS 10.0) flaw in an internal API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that arises from a lack of file validation checks, allowing uploaded files to be placed in privileged directories. An unauthenticated, remote attacker triggers it by uploading a crafted file to the vulnerable API, with no credentials or user interaction required. A successful exploit lets the attacker execute those files on the underlying operating system as root, yielding arbitrary code execution and full system compromise (high confidentiality, integrity, and availability impact, with scope changed). Any organization running Cisco ISE or ISE-PIC — Cisco's enterprise network access control (NAC) platforms — is potentially affected, with risk highest where the API is reachable beyond tightly controlled management networks. Cisco has confirmed active exploitation of the unauthenticated-root ISE flaws according to news reports, and the flaw carries an elevated 27% EPSS probability of exploitation within 30 days (98th percentile), although the provided data does not yet list it in the CISA KEV.

What to do: Upgrade Cisco ISE and ISE-PIC nodes to the fixed releases specified in Cisco's PSIRT advisory (the provided data does not include version numbers), prioritizing deployments where the API surface is reachable from broader networks. Until patching is complete, restrict network access to the ISE/ISE-PIC API interfaces and audit affected systems for unexpected files in privileged directories and new root-level processes.

Affected
Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
Estimated exposure
largetens of thousands of enterprise deployments (roughly 10,000–100,000 ISE/ISE-PIC systems) — Cisco publishes no active-install or internet-exposed device count for ISE, so this is an order-of-magnitude estimate based on ISE/ISE-PIC's role as Cisco's flagship NAC platform, typically deployed as dedicated appliance/VM nodes at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.

Vendors
cisco
Products
identity services engine, identity services engine passive identity connector
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news