CISA Warns of Exploited Vulnerabilities in Cisco Products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-2533 | CSRF Flaw in PaperCut NG/MF Enables Security Changes and Arbitrary Code Execution CVE-2023-2533 is a cross-site request forgery (CSRF, CWE-352) flaw in PaperCut's NG and MF print-management software, where state-changing requests submitted through the product's web console are not adequately verified as originating from a trusted source. An attacker triggers it by persuading an authenticated PaperCut administrator or user to follow attacker-controlled content, such as a crafted link, while their web session is active. Under specific conditions, the attacker can then alter security settings or execute arbitrary code in the context of the victim's session. Any organization running PaperCut NG or MF is potentially affected, though the available data does not specify exact affected or fixed version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-28, confirming active exploitation; no public proof-of-concept is known and CVSS is not yet scored, but EPSS puts the probability of exploitation within 30 days at 29.2% (98th percentile). Do: Apply PaperCut's mitigations per the vendor's security advisory, including upgrading NG and MF to the fixed release specified there, and audit recent security-setting changes for signs of tampering; federal users must follow applicable BOD 22-01 guidance (including for cloud services) or discontinue use if mitigations are unavailable. Since CSRF requires an active authenticated session, restrict admin-console access and treat phishing links aimed at PaperCut administrators as a live vector. | 8.8 | 29% | KEV PoC |
| largetens of thousands to ~100,000 organizations running PaperCut NG/MF (vendor cites 100k+ deployments), with only a subset of instances internet-exposed | |
| CVE-2025-20281 | Unauthenticated Root RCE via API Injection in Cisco ISE and ISE-PIC CVE-2025-20281 is an injection flaw (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to that API; no valid credentials or user interaction are required. A successful exploit yields arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device (scope-changing per the CVSS 10.0 score). Any organization running affected ISE or ISE-PIC releases is exposed, particularly where the vulnerable API is reachable from untrusted networks. The flaw is confirmed under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-28, EPSS assigns a 97.1% probability of exploitation within 30 days, and ZDI has published a writeup of the unauthenticated root RCE. Do: Upgrade Cisco ISE and ISE-PIC to the patched releases specified in Cisco's PSIRT advisory, and check whether the vulnerable API/admin interface is reachable from untrusted networks, restricting access until patching is complete. As a KEV entry added 2025-07-28, U.S. federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product; given EPSS of 97.1% and confirmed active exploitation, prioritize internet-facing ISE instances and review API/web-server logs for signs of exploitation. | 10.0 | 97% | KEV PoC |
| largeroughly tens of thousands of enterprise/government deployments worldwide (estimate), with an unknown subset exposing the vulnerable API to untrusted networks | |
| CVE-2025-20337 | Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known. Do: Upgrade Cisco ISE and ISE-PIC to the fixed releases identified in Cisco's security advisory (fixed version details are not included in this data set), and check management/API logs for unauthenticated crafted API requests indicating exploitation. As an interim mitigation, restrict network access to the affected API and the ISE administration interface. Organizations covered by BOD 22-01 must apply vendor mitigations per Cisco's instructions or discontinue use of the product by the KEV remediation deadline. | 10.0 | 68% | KEV |
| moderatelikely on the order of tens of thousands of enterprise deployments worldwide (deployment-pattern estimate; no public install or scan counts) |
Full article327 words · extracted from infosecurity-magazine.com · click to collapse
The US Cybersecurity and Infrastructure Security Agency (CISA) added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 28.
These include two highly critical vulnerabilities in Cisco Identity Services Engine (ISE) Software, a network security policy management platform that provides secure access control, authentication, authorization and accounting (AAA) services for users and devices connecting to enterprise networks.
Both vulnerabilities, tracked as CVE-2025-20281 and CVE-2025-20337, were discovered by security researchers working with the Trend Micro Zero Day Initiative and disclosed by Cisco on June 25.
They have been identified due to insufficient validation of a user-supplied input in a specific API of Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC).
Attackers can exploit each by submitting a crafted API request. When exploited, it allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. It can lead the attacker to obtain root privileges on an affected device.
Both vulnerabilities affect the following versions of Cisco ISE:
- 3.3.0
- 3.3 Patch 2
- 3.3 Patch 1
- 3.3 Patch 3
- 3.4.0
- 3.3 Patch 4
- 3.4 Patch 1
- 3.3 Patch 5
- 3.3 Patch 6
Additionally, CVE-2025-20337 also affects Cisco ISE-PIC’s versions 3.1.0, 3.2.0, 3.3.0 and 3.4.0.
They are both rated with the highest severity level, with a CVSS3.1 score of 10.
Cisco has released patches for each affected version of Cisco ISE and Cisco ISE-PIC.
Cisco Product Security Incident Response Team (PSIRT) has become aware of attempted exploitation of both vulnerabilities in the wild.
CISA has set August 18 as the deadline for remediation, requiring organizations to address these critical security vulnerabilities within the next three weeks. No workaround is available besides applying the patches.
The third vulnerability added to CISA’s KEV list on July 28, CVE-2023-2533, is a high-severity cross-site request forgery (CSRF) vulnerability affecting PaperCut Next Generation (NG) and Multi-Function (MF), print management software solutions designed to help organizations control, monitor and optimize printing, copying, scanning and faxing across their networks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-kev-cisco-ise/