PT-2025-26847 · Cisco · Cisco Ise-Pic +1

Bobby Gould

+1

·

Published

2025-06-25

·

Updated

2025-07-24

·

CVE-2025-20281

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Cisco ISE and Cisco ISE-PIC versions 3.3 through 3.4

Cisco ISE and Cisco ISE-PIC (affected versions not specified)

**Description:**

A vulnerability exists in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input. This allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this issue. This vulnerability is actively exploited.

**Recommendations:**

Cisco ISE versions prior to 3.3 Patch 7 are vulnerable.

Cisco ISE-PIC versions prior to 3.4 Patch 2 are vulnerable.

Fix

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08248
CVE-2025-20281
ZDI-25-609

Affected Products

Cisco Ise
Cisco Ise-Pic