ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2533
CSRF Flaw in PaperCut NG/MF Enables Security Changes and Arbitrary Code Execution

CVE-2023-2533 is a cross-site request forgery (CSRF, CWE-352) flaw in PaperCut's NG and MF print-management software, where state-changing requests submitted through the product's web console are not adequately verified as originating from a trusted source. An attacker triggers it by persuading an authenticated PaperCut administrator or user to follow attacker-controlled content, such as a crafted link, while their web session is active. Under specific conditions, the attacker can then alter security settings or execute arbitrary code in the context of the victim's session. Any organization running PaperCut NG or MF is potentially affected, though the available data does not specify exact affected or fixed version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-28, confirming active exploitation; no public proof-of-concept is known and CVSS is not yet scored, but EPSS puts the probability of exploitation within 30 days at 29.2% (98th percentile).

Do: Apply PaperCut's mitigations per the vendor's security advisory, including upgrading NG and MF to the fixed release specified there, and audit recent security-setting changes for signs of tampering; federal users must follow applicable BOD 22-01 guidance (including for cloud services) or discontinue use if mitigations are unavailable. Since CSRF requires an active authenticated session, restrict admin-console access and treat phishing links aimed at PaperCut administrators as a live vector.

8.829% KEV PoC
  • PaperCut NG/MF
largetens of thousands to ~100,000 organizations running PaperCut NG/MF (vendor cites 100k+ deployments), with only a subset of instances internet-exposed
CVE-2025-20281
+1 in the same advisory: …20282
Unauthenticated Root RCE via API Injection in Cisco ISE and ISE-PIC

CVE-2025-20281 is an injection flaw (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to that API; no valid credentials or user interaction are required. A successful exploit yields arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device (scope-changing per the CVSS 10.0 score). Any organization running affected ISE or ISE-PIC releases is exposed, particularly where the vulnerable API is reachable from untrusted networks. The flaw is confirmed under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-28, EPSS assigns a 97.1% probability of exploitation within 30 days, and ZDI has published a writeup of the unauthenticated root RCE.

Do: Upgrade Cisco ISE and ISE-PIC to the patched releases specified in Cisco's PSIRT advisory, and check whether the vulnerable API/admin interface is reachable from untrusted networks, restricting access until patching is complete. As a KEV entry added 2025-07-28, U.S. federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product; given EPSS of 97.1% and confirmed active exploitation, prioritize internet-facing ISE instances and review API/web-server logs for signs of exploitation.

10.097% KEV PoC
  • Cisco Identity Services Engine (ISE)
  • Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
largeroughly tens of thousands of enterprise/government deployments worldwide (estimate), with an unknown subset exposing the vulnerable API to untrusted networks
CVE-2025-20337
Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC

CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

Do: Upgrade Cisco ISE and ISE-PIC to the fixed releases identified in Cisco's security advisory (fixed version details are not included in this data set), and check management/API logs for unauthenticated crafted API requests indicating exploitation. As an interim mitigation, restrict network access to the affected API and the ISE administration interface. Organizations covered by BOD 22-01 must apply vendor mitigations per Cisco's instructions or discontinue use of the product by the KEV remediation deadline.

10.068% KEV
  • Cisco Identity Services Engine (ISE)
  • Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
moderatelikely on the order of tens of thousands of enterprise deployments worldwide (deployment-pattern estimate; no public install or scan counts)
Full article685 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-20281 Cisco Identity Services Engine Injection Vulnerability
  • CVE-2025-20337 Cisco Identity Services Engine Injection Vulnerability
  • CVE-2023-2533 PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability

This week, Cisco confirmed attempted exploitation in the wild of recently disclosed ISE and ISE-PIC flaws (CVE-2025-20281CVE-2025-20282CVE-2025-20337), updating its advisory after detecting attacks in July 2025.

“Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.” reads the advisory. “In July 2025, the Cisco PSIRT became aware of attempted exploitation of some of these vulnerabilities in the wild. Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate these vulnerabilities.”

In June, Cisco addressed the critical vulnerabilities CVE-2025-20281 and CVE-2025-20282 in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could allow remote, unauthenticated attackers to execute arbitrary code with root privileges.

“Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.” reads the advisory.

CVE-2025-20281 (CVSS score of 10) affects Cisco ISE/ISE-PIC 3.3+, while CVE-2025-20282 (CVSS score of 10) impacts only version 3.4. Versions outside these ranges are not impacted.

CVE-2025-20281 is a critical flaw in Cisco ISE/ISE-PIC allowing unauthenticated remote attackers to execute code as root via a vulnerable API.

“This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request.” continues the advisory. “A successful exploit could allow the attacker to obtain root privileges on an affected device.”

The second flaw, tracked as CVE-2025-20282, is a critical issue in Cisco ISE/ISE-PIC allowing unauthenticated remote attackers to upload and execute files as root via an internal API.

“This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device.” reads the advisory. “A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.”

Last week, Cisco addressed the critical vulnerability CVE-2025-20337 (CVSS score of 10) in Identity Services Engine (ISE) and Cisco Identity Services Engine Passive Identity Connector (ISE-PIC). An attacker could trigger the vulnerability to execute arbitrary code on the underlying operating system with root privileges.

“Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.” reads the report published by the IT giant.

The vulnerability CVE-2025-20337 is similar to CVE-2025-20281.

Cisco did not share details about the attacks exploiting the flaws and the threat actors behind them.

The vulnerability CVE-2023-2533 (CVSS score of 8.4) is a Cross-Site Request Forgery (CSRF) vulnerability in PaperCut NG/MF, which, under specific conditions, could potentially allow an attacker to alter security settings or execute arbitrary code. The experts warn that admin session hijack is possible via a crafted malicious link. An attacker can trick logged-in admin to trigger unauthorized actions.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by August 18, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cisa)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/180494/security/u-s-cisa-adds-cisco-ise-and-papercut-ng-mf-flaws-to-its-known-exploited-vulnerabilities-catalog.html