Vulnslist

find the latest Cisco vulnerabilities

Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities

cisco-sa-ise-unauth-rce-ZAd2GnJ6 · Critical · Published · Updated

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.  For more information about these vulnerabilities, see the Details section of this advisory.  Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Note: Since the publication of version 1.0 of this advisory, improved fixed releases have become available. Cisco recommends upgrading to an enhanced fixed release as follows: If Cisco ISE is running Release 3.4 Patch 2, no further action is necessary. If Cisco ISE is running Release 3.3 Patch 6, additional fixes are available in Release 3.3 Patch 7, and the device must be upgraded. If Cisco ISE has either hot patch ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz or hot patch ise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz installed, Cisco recommends upgrading to Release 3.3 Patch 7 or Release 3.4 Patch 2. The hot patches did not address CVE-2025-20337 and have been deferred from CCO. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6

Workarounds

There are no workarounds that address these vulnerabilities.

CVEsCVE-2025-20281, CVE-2025-20282, CVE-2025-20337
Cisco Bug IDsCSCwp02821, CSCwo99449, CSCwp02814
CVSS ScoreBase 10.0
Base 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Identity Services Engine Software, Cisco ISE Passive Identity Connector

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Identity Services Engine Software known_affected cisco_csaf CVE-2025-20281, CVE-2025-20282, CVE-2025-20337 3
Cisco ISE Passive Identity Connector known_affected cisco_csaf CVE-2025-20337 1

Related Products

Product CVE Evidence
Cisco Identity Services Engine Software CVE-2025-20281 Cisco OpenVuln
Cisco ISE Passive Identity Connector CVE-2025-20281 Cisco OpenVuln
Cisco Identity Services Engine Software CVE-2025-20337 Cisco OpenVuln
Cisco ISE Passive Identity Connector CVE-2025-20337 Cisco OpenVuln
Cisco Identity Services Engine Software CVE-2025-20282 Cisco OpenVuln
Cisco ISE Passive Identity Connector CVE-2025-20282 Cisco OpenVuln