ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Maximum severity Cisco ISE vulnerabilities exploited by attackers

criticalVulnerability exploited in the wildimportance 60CVE-2025-20281CVE-2025-20337CVE-2025-20282

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20281
+1 in the same advisory: …20282
Unauthenticated Root RCE via API Injection in Cisco ISE and ISE-PIC

CVE-2025-20281 is an injection flaw (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to that API; no valid credentials or user interaction are required. A successful exploit yields arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device (scope-changing per the CVSS 10.0 score). Any organization running affected ISE or ISE-PIC releases is exposed, particularly where the vulnerable API is reachable from untrusted networks. The flaw is confirmed under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-28, EPSS assigns a 97.1% probability of exploitation within 30 days, and ZDI has published a writeup of the unauthenticated root RCE.

Do: Upgrade Cisco ISE and ISE-PIC to the patched releases specified in Cisco's PSIRT advisory, and check whether the vulnerable API/admin interface is reachable from untrusted networks, restricting access until patching is complete. As a KEV entry added 2025-07-28, U.S. federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product; given EPSS of 97.1% and confirmed active exploitation, prioritize internet-facing ISE instances and review API/web-server logs for signs of exploitation.

10.097% KEV PoC
  • Cisco Identity Services Engine (ISE)
  • Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
largeroughly tens of thousands of enterprise/government deployments worldwide (estimate), with an unknown subset exposing the vulnerable API to untrusted networks
CVE-2025-20337
Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC

CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

Do: Upgrade Cisco ISE and ISE-PIC to the fixed releases identified in Cisco's security advisory (fixed version details are not included in this data set), and check management/API logs for unauthenticated crafted API requests indicating exploitation. As an interim mitigation, restrict network access to the affected API and the ISE administration interface. Organizations covered by BOD 22-01 must apply vendor mitigations per Cisco's instructions or discontinue use of the product by the KEV remediation deadline.

10.068% KEV
  • Cisco Identity Services Engine (ISE)
  • Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
moderatelikely on the order of tens of thousands of enterprise deployments worldwide (deployment-pattern estimate; no public install or scan counts)
Full article325 words · extracted from helpnetsecurity.com · click to collapse

One or more vulnerabilities affecting Cisco Identity Services Engine (ISE) are being exploited in the wild, Cisco has confirmed by updating the security advisory for the flaws.

About the vulnerabilities

The three vulnerabilities affect Cisco’s Identity Services Engine (ISE) – a network security policy and access control system for enterprises – and Cisco ISE Passive Identity Connector (ISE-PIC), which is a lightweight identity service that allows Cisco ISE to passively gather user identity information.

CVE-2025-20281 and CVE-2025-20337 stem from insufficient validation of user-supplied input; can be triggered by remote, unauthenticated attackers sending a maliciously crafted API request; and may allow them to obtain root privileges on an affected device.

CVE-2025-20282 is due to a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system, and may allow unauthenticated, remote attackers to stash malicious files on vulnerable systems, so they can execute arbitrary code or obtain root privileges on them.

“The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability,” the company said.

Cisco did not specify which of the three vulnerabilities are being probed/exploited, nor share details about the attacks, which they say have been spotted in July 2025.

The company patched CVE-2025-20281 and CVE-2025-20282 in late June, then updated the code fix to patch CVE-2025-20337 a week ago.

Customers who use Cisco ISE or ISE-PIC versions 3.2 or earlier are not in danger, but those running versions 3.3 and 3.4 are urged to upgrade to v3.3 Patch 7 or v3.4 Patch 2 as soon as possible, as there are no workarounds available to mitigate the risk of exploitation.

UPDATE (July 25, 2025, 04:35 a.m. ET):

Cisco has cleared up that it’s CVE-2025-20281 and CVE-2025-20337 attackers have been exploiting in the wild.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/23/maximum-severity-cisco-ise-vulnerabilities-exploited-by-attackers/