PT-2025-26847 · Cisco · Cisco Ise-Pic+1

Bobby Gould

+1

·

Published

2025-06-25

·

Updated

2026-03-11

·

CVE-2025-20281

CVSS v3.1

10

Critical

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine and Cisco ISE-PIC versions 3.3 and later Cisco ISE versions prior to 3.3 Patch 7 Cisco ISE versions prior to 3.4 Patch 2
Description A vulnerability exists in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input. This allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The vulnerability is actively exploited and a complete exploit chain has been published. The API abuse of this vulnerability was observed in the CoinDCX breach. The vulnerability allows attackers to send crafted API requests to execute commands without requiring valid credentials.
Recommendations Update Cisco ISE to version 3.3 Patch 7 or later. Update Cisco ISE to version 3.4 Patch 2 or later.

Exploit

Fix

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08248
CVE-2025-20281
ZDI-25-609

Affected Products

Cisco Ise
Cisco Ise-Pic