PT-2025-26847 · Cisco · Cisco Ise-Pic+1
Bobby Gould
+1
·
Published
2025-06-25
·
Updated
2026-03-11
·
CVE-2025-20281
CVSS v3.1
10
Critical
| AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine and Cisco ISE-PIC versions 3.3 and later
Cisco ISE versions prior to 3.3 Patch 7
Cisco ISE versions prior to 3.4 Patch 2
Description
A vulnerability exists in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input. This allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The vulnerability is actively exploited and a complete exploit chain has been published. The API abuse of this vulnerability was observed in the CoinDCX breach. The vulnerability allows attackers to send crafted API requests to execute commands without requiring valid credentials.
Recommendations
Update Cisco ISE to version 3.3 Patch 7 or later.
Update Cisco ISE to version 3.4 Patch 2 or later.
Exploit
Fix
RCE
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ise
Cisco Ise-Pic