CVE-2025-20284

MEDIUM

Cisco Identity Services Engine - Authenticated Remote Code Execution via API Request

Title source: llm
STIX 2.1

Description

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, the attacker must have valid high-privileged credentials.

Scores

CVSS v3 6.5
EPSS 0.0076
EPSS Percentile 73.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (6)
cisco/identity_services_engine 3.3.0 (7 CPE variants)
cisco/identity_services_engine 3.4.0 (2 CPE variants)
cisco/identity_services_engine < 3.3.0
cisco/identity_services_engine_passive_identity_connector 3.3.0 (7 CPE variants)
cisco/identity_services_engine_passive_identity_connector 3.4.0 (2 CPE variants)
cisco/identity_services_engine_passive_identity_connector < 3.3.0
Published Jul 16, 2025
Tracked Since Feb 18, 2026