Cisco Warns of Critical ISE Flaw Allowing Unauthenticated Attackers to Execute Root Code
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-20281 +1 in the same advisory: …20282 | Unauthenticated Root RCE via API Injection in Cisco ISE and ISE-PIC CVE-2025-20281 is an injection flaw (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by sending a crafted request to that API; no valid credentials or user interaction are required. A successful exploit yields arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device (scope-changing per the CVSS 10.0 score). Any organization running affected ISE or ISE-PIC releases is exposed, particularly where the vulnerable API is reachable from untrusted networks. The flaw is confirmed under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-28, EPSS assigns a 97.1% probability of exploitation within 30 days, and ZDI has published a writeup of the unauthenticated root RCE. Do: Upgrade Cisco ISE and ISE-PIC to the patched releases specified in Cisco's PSIRT advisory, and check whether the vulnerable API/admin interface is reachable from untrusted networks, restricting access until patching is complete. As a KEV entry added 2025-07-28, U.S. federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product; given EPSS of 97.1% and confirmed active exploitation, prioritize internet-facing ISE instances and review API/web-server logs for signs of exploitation. | 10.0 | 97% | KEV PoC |
| largeroughly tens of thousands of enterprise/government deployments worldwide (estimate), with an unknown subset exposing the vulnerable API to untrusted networks | |
| CVE-2025-20286 | A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) c A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2025-20337 | Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known. Do: Upgrade Cisco ISE and ISE-PIC to the fixed releases identified in Cisco's security advisory (fixed version details are not included in this data set), and check management/API logs for unauthenticated crafted API requests indicating exploitation. As an interim mitigation, restrict network access to the affected API and the ISE administration interface. Organizations covered by BOD 22-01 must apply vendor mitigations per Cisco's instructions or discontinue use of the product by the KEV remediation deadline. | 10.0 | 68% | KEV |
| moderatelikely on the order of tens of thousands of enterprise deployments worldwide (deployment-pattern estimate; no public install or scan counts) | |
| CVE-2025-25257 | Critical Unauthenticated SQL Injection in Fortinet FortiWeb (CVE-2025-25257) CVE-2025-25257 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in Fortinet's FortiWeb web application firewall, affecting FortiWeb 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, and 7.0.0 through 7.0.10. It can be triggered by an unauthenticated remote attacker sending crafted HTTP or HTTPS requests to the appliance, with no user interaction or credentials required. Successful exploitation lets the attacker execute unauthorized SQL commands or code on the device, and publicly released proof-of-concept exploits chain the flaw to remote code execution on the appliance. Any organization running an affected FortiWeb version is exposed, and because FortiWeb appliances are typically deployed at the network edge to protect web applications, internet-facing deployments are the most likely targets. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-18 and carries a 99.8% EPSS score with two public PoC exploits, so defenders should treat it as actively exploited. Do: Upgrade FortiWeb to the latest patched build for your branch (7.0.x, 7.2.x, 7.4.x, or 7.6.x) per Fortinet's advisory, or apply the vendor's mitigations; federal agencies must follow the BOD 22-01 requirements tied to the KEV listing. Until patched, limit internet exposure of FortiWeb interfaces and review device and WAF logs for signs of exploitation, since public PoC exploits and the KEV addition on 2025-07-18 indicate active use. | 9.8 | 100% | KEV PoC ×2 |
| largetens of thousands of internet-exposed FortiWeb appliances (estimated) |
Full article427 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 17, 2025Vulnerability / Network Security
Cisco has disclosed a new maximum-severity security vulnerability impacting Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that could permit an attacker to execute arbitrary code on the underlying operating system with elevated privileges.
Tracked as CVE-2025-20337, the shortcoming carries a CVSS score of 10.0 and is similar to CVE-2025-20281, which was patched by the networking equipment major late last month.
"Multiple vulnerabilities in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit these vulnerabilities," the company said in an updated advisory.
"These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device."
Kentaro Kawane of GMO Cybersecurity has been credited with discovering and reporting the flaw. Kawane was previously acknowledged for two other critical Cisco ISE flaws (CVE-2025-20286 and CVE-2025-20282) and another critical bug in Fortinet FortiWeb (CVE-2025-25257)
CVE-2025-20337 affects ISE and ISE-PIC releases 3.3 and 3.4, regardless of device configuration. It does not impact ISE and ISE-PIC release 3.2 or earlier. The issue has been patched in the following versions -
- Cisco ISE or ISE-PIC Release 3.3 (Fixed in 3.3 Patch 7)
- Cisco ISE or ISE-PIC Release 3.4 (Fixed in 3.4 Patch 2)
There is no evidence that the vulnerability has been exploited in a malicious context. That said, it's always a good practice to ensure that systems are kept up-to-date to avoid potential threats.
The disclosure comes as The Shadowserver Foundation reported that threat actors are likely exploiting publicly released exploits associated with CVE-2025-25257 to drop web shells on susceptible Fortinet FortiWeb instances since July 11, 2025.
As of July 15, there are estimated to be 77 infected instances, down from 85 the day before. The majority of the compromises are concentrated around North America (44), Asia (14), and Europe (13).
Data from the attack surface management platform Censys shows that there are 20,098 Fortinet FortiWeb appliances online, excluding honeypots, although it's currently not known how many of these are vulnerable to CVE-2025-25257.
"This flaw enables unauthenticated attackers to execute arbitrary SQL commands via crafted HTTP requests, leading to remote code execution (RCE)," Censys said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/07/cisco-warns-of-critical-ise-flaw.html