CVE-2025-20337
9.5 CISA KEVCisco · Identity Services Engine
An injection vulnerability in the Cisco Identity Services Engine API allows unauthenticated remote attackers to execute arbitrary code as root.
Executive summary
A critical remote code execution vulnerability in Cisco Identity Services Engine is currently being exploited in the wild, posing an immediate risk of full system compromise.
Vulnerability
This is an injection flaw (CWE-74) resulting from insufficient input validation in a specific API. An unauthenticated attacker can execute arbitrary code with root privileges by sending a crafted API request.
Business impact
Successful exploitation grants an attacker full root-level control over the affected Cisco ISE appliance. Given the central role of ISE in network access control, this vulnerability leads to unauthorized administrative access, potential data exfiltration, and total loss of network security integrity. The CVSS score of 9.5 reflects the critical nature of this vulnerability, which is compounded by active exploitation in real-world environments.
Remediation
Immediate Action: Apply the vendor-supplied security updates or patches as detailed in the Cisco security advisory immediately. If patching is not feasible, restrict access to the affected management interfaces to trusted networks only.
Proactive Monitoring: Review system logs for suspicious API requests or unexpected process execution originating from the web management interface. Monitor for unusual outbound traffic from the ISE appliances that may indicate post-exploitation activity.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to inspect and sanitize incoming API traffic to the Cisco ISE platform. Ensure that management interfaces are not exposed to the public internet.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as referenced in the GitHub repository B1ack4sh/Blackash-CVE-2025-20337.
Analyst recommendation
The severity of CVE-2025-20337 cannot be overstated, as it provides a direct path to total system takeover without authentication. Organizations must prioritize the application of vendor-provided patches or mitigations to neutralize this threat. Given the confirmed active exploitation, failure to act leaves the network infrastructure exposed to immediate and severe risk.
More Cisco CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief critical section
- Look Back published
- Analyst report written