Max severity Cisco ISE bug allows pre-auth command execution, patch now
Score: 72/100
5 articles
100.0% Similarity
13 hours ago
Activity Timeline
Critical Cisco ISE Vulnerability Allows Remote Att...
Cybersecurity News
Jul 17
02:39
Cisco Patches Another Critical ISE Vulnerability...
SecurityWeek
Jul 17
08:22
Cisco Unified Intelligence Center Flaw Lets Remote...
GB Hackers
Jul 17
08:29
Cisco Unified Intelligence Center Vulnerability Al...
Cybersecurity News
Jul 17
08:41
Max severity Cisco ISE bug allows pre-auth command...
BleepingComputer
Primary Article
Jul 17
15:53
Primary Article
BleepingComputer 7 hours ago
Max severity Cisco ISE bug allows pre-auth command execution, patch now
Bill Toulas
July 17, 2025
11:53 AM
0
A critical vulnerability (CVE-2025-20337) in Cisco's Identity Services Engine (ISE) could be exploited to let an unauthenticated attacker store malicious files, execute arbitrary code, or gain root privileges on vulnerable devices.
The security issue received the maximum severity rating, 10 out of 10, and is caused by insufficient user-supplied input validation checks.
It was discovered by Kentaro Kawane, a researcher at the Japanese cybersecurity service GMO Cybersecurity by Ierae, and reported Trend Micro's Zero Day Initiative (ZDI).
A remote unauthenticated attacker could leverage it by submitting a specially crafted API request
The vulnerability was added via anupdate to the security bulletinfor CVE-2025-20281 and CVE-2025-20282, twosimilar RCE vulnerabilitiesthat also received the maximum severity score, that impact ISE and ISE-PIC versions 3.4 and 3.3.
"These vulnerabiliti...
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Unlock Cluster AI
Join ThreatCluster Intelligence to access AI-generated executive, technical, and remediation briefs.
Cisco on Wednesday informed customers of another critical-severity vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could lead to remote code execution...
A critical vulnerability in Cisco’s Unified Intelligence Center (CUIC) web-based management interface has been classified with high severity, allowing authenticated remote attackers with Report Design...
Cisco Unified Intelligence Center Flaw Lets Remote Attackers Upload Arbitrary Files
A critical security vulnerability has been discovered in Cisco’s Unified Intelligence Center that allows authenticat...
Cisco has disclosed multiple critical security vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could allow unauthenticated remote attackers to e...
Save to Folder
Choose a folder to save this cluster:
We use cookies
We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.
Cookie Settings
Essential Cookies
Required for the website to function. Cannot be disabled.
Session management and authentication
Security and fraud prevention
Cookie consent preferences
Analytics Cookies
Help us understand how visitors interact with our website.