CVE-2025-20337

9.5 CISA KEV

Cisco · Identity Services Engine

An injection vulnerability in the Cisco Identity Services Engine API allows unauthenticated remote attackers to execute arbitrary code as root.

Executive summary

A critical remote code execution vulnerability in Cisco Identity Services Engine is currently being exploited in the wild, posing an immediate risk of full system compromise.

Vulnerability

This is an injection flaw (CWE-74) resulting from insufficient input validation in a specific API. An unauthenticated attacker can execute arbitrary code with root privileges by sending a crafted API request.

Business impact

Successful exploitation grants an attacker full root-level control over the affected Cisco ISE appliance. Given the central role of ISE in network access control, this vulnerability leads to unauthorized administrative access, potential data exfiltration, and total loss of network security integrity. The CVSS score of 9.5 reflects the critical nature of this vulnerability, which is compounded by active exploitation in real-world environments.

Remediation

Immediate Action: Apply the vendor-supplied security updates or patches as detailed in the Cisco security advisory immediately. If patching is not feasible, restrict access to the affected management interfaces to trusted networks only.

Proactive Monitoring: Review system logs for suspicious API requests or unexpected process execution originating from the web management interface. Monitor for unusual outbound traffic from the ISE appliances that may indicate post-exploitation activity.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to inspect and sanitize incoming API traffic to the Cisco ISE platform. Ensure that management interfaces are not exposed to the public internet.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as referenced in the GitHub repository B1ack4sh/Blackash-CVE-2025-20337.

Analyst recommendation

The severity of CVE-2025-20337 cannot be overstated, as it provides a direct path to total system takeover without authentication. Organizations must prioritize the application of vendor-provided patches or mitigations to neutralize this threat. Given the confirmed active exploitation, failure to act leaves the network infrastructure exposed to immediate and severe risk.

More Cisco CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Published in the daily brief critical section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief critical section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief critical section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Published in the daily brief critical section
  24. Look Back published
  25. Analyst report written

Sources