CVE-2025-20282
largeUnauthenticated File-Upload RCE with Root Privileges in Cisco ISE and ISE-PIC
CVE-2025-20282 is a critical (CVSS 10.0) flaw in an internal API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that arises from a lack of file validation checks, allowing uploaded files to be placed in privileged directories. An unauthenticated, remote attacker triggers it by uploading a crafted file to the vulnerable API, with no credentials or user interaction required. A successful exploit lets the attacker execute those files on the underlying operating system as root, yielding arbitrary code execution and full system compromise (high confidentiality, integrity, and availability impact, with scope changed). Any organization running Cisco ISE or ISE-PIC — Cisco's enterprise network access control (NAC) platforms — is potentially affected, with risk highest where the API is reachable beyond tightly controlled management networks. Cisco has confirmed active exploitation of the unauthenticated-root ISE flaws according to news reports, and the flaw carries an elevated 27% EPSS probability of exploitation within 30 days (98th percentile), although the provided data does not yet list it in the CISA KEV.
What to do: Upgrade Cisco ISE and ISE-PIC nodes to the fixed releases specified in Cisco's PSIRT advisory (the provided data does not include version numbers), prioritizing deployments where the API surface is reachable from broader networks. Until patching is complete, restrict network access to the ISE/ISE-PIC API interfaces and audit affected systems for unexpected files in privileged directories and new root-level processes.
| Cisco Identity Services Engine (ISE) | — |
| Cisco Identity Services Engine Passive Identity Connector (ISE-PIC) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.
- Vendors
- cisco
- Products
- identity services engine, identity services engine passive identity connector
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H