CVE-2025-20125
published 2025-02-05CVE-2025-20125: A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change…
PriorityP262high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EXPLOIT
EPSS
14.98%
96.3th percentile
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node.
This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device.
Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
Affected
40 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for HTTP GET requests to /api/v1/admin/config/export from read-only administrative accounts, which should not normally access this endpoint. ↗
- →Detect the exploit tool's distinctive User-Agent string 'Mozilla/5.0 (compatible; ISE-Exploit)' in HTTP requests to Cisco ISE API endpoints. ↗
- →Flag unexpected node reloads or configuration exports initiated via the REST API, particularly from read-only administrative sessions, as potential exploitation of CVE-2025-20125. ↗
- →Correlate ISE API access using the ISESSIONID cookie from accounts that only hold read-only administrative roles against sensitive admin API paths. ↗
- ·Exploitation requires valid read-only administrative credentials; unauthenticated exploitation is not possible. ↗
- ·In a single-node ISE deployment, a successful reboot exploit will prevent new devices from authenticating during the reload window, causing an availability impact. ↗
- ·There are no workarounds available; the only mitigation is applying Cisco's software updates. ↗
- ·CVE-2025-20125 is tracked under Cisco Bug IDs CSCwk14901 and CSCwk14916 and is classified under CWE-285 (Improper Authorization) and CWE-502 (Deserialization of Untrusted Data). ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.9CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
vendor_cisco·2025-02-05·CVSS 9.9
CVE-2025-20124 [CRITICAL] CWE-285 Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands and elevate privileges on an affected device.
Note: To exploit these vulnerabilities, an attacker must have valid ISE administrative credentials. These vulnerabilities can be exploited using any valid administrative account, including read-only administrative accounts.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.
Cisco
Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20125 Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
CVE-2025-20125: Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands and elevate privileges on an affected device. Note: To exploit these vulnerabilities, an attacker must have valid ISE administrative credentials. These vulnerabilities can be exploited using any valid administrative account, including read-only administrative accounts. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-285, CWE-502, CWE-285, CWE-502
Bug IDs: CSCwk14901, CSCwk14916, CSCwk14916, CSCwk14901
GHSA
GHSA-hrpp-92f9-h887: A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information,
ghsa_unreviewed·2025-02-05
CVE-2025-20125 [CRITICAL] CWE-285 GHSA-hrpp-92f9-h887: A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information,
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node.
This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device.
Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
No detection rules found.
Checkpoint
10th February – Threat Intelligence Report
blogs_checkpoint·2025-02-10
CVE-2025-0994 10th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th February, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Grubhub, the US-based online food ordering and delivery platform, suffered a data breach due to unauthorized access through a compromised third-party service provider’s account. The incident exposed personal details of customers, drivers, and merchants, including names, email addresses, phone numbers, payment card types
Bleepingcomputer
Critical Cisco ISE bug can let attackers run commands as root
blogs_bleepingcomputer·2025-02-06·CVSS 9.9
CVE-2025-20124 [CRITICAL] Critical Cisco ISE bug can let attackers run commands as root
## Critical Cisco ISE bug can let attackers run commands as root
## Sergiu Gatlan
Cisco has released patches to fix two critical vulnerabilities in its Identity Services Engine (ISE) security policy management platform.
Enterprise administrators use Cisco ISE as an identity and access management (IAM) solution that combines authentication, authorization, and accounting into a single appliance.
The two security flaws (CVE-2025-20124 and CVE-2025-20125) can be exploited by authenticated remote attackers with read-only admin privileges to execute arbitrary commands as root and bypass authorization on unpatched devices.
These vulnerabilities impact Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC) appliances, regardless of device configuration.
"This vulnerability is due to in
2025-02-05
Published