PT-2025-29858 · Cisco · Cisco Ise +1

Kentaro Kawane

·

Published

2025-06-25

·

Updated

2025-09-08

·

CVE-2025-20337

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) versions 3.3 and 3.4 Cisco ISE-PIC versions 3.3 and 3.4
Description A critical vulnerability exists in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input. This allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system with root privileges by submitting a crafted API request. No valid credentials are required for exploitation.
Recommendations Upgrade Cisco Identity Services Engine version 3.3 to Patch 7. Upgrade Cisco Identity Services Engine version 3.4 to Patch 2. Upgrade Cisco ISE-PIC version 3.3 to Patch 7. Upgrade Cisco ISE-PIC version 3.4 to Patch 2.

Fix

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-08631
CVE-2025-20337
ZDI-25-607

Affected Products

Cisco Ise
Cisco Ise-Pic