CVE-2025-20282
published 2025-06-25CVE-2025-20282: A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected…
PriorityP196critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
9.80%
95.0th percentile
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.
This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_unauthenticated | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-20282 affects only Cisco ISE and ISE-PIC Release 3.4; exploit involves uploading arbitrary files via an internal API to privileged directories and executing them as root — monitor for unexpected file writes to privileged directories on ISE appliances ↗
- →Active exploitation of CVE-2025-20282 (alongside CVE-2025-20281 and CVE-2025-20337) was confirmed in July 2025; treat any anomalous unauthenticated requests to Cisco ISE internal APIs as high-priority alerts ↗
- →The vulnerability is triggered via an unauthenticated request to an internal API endpoint; monitor ISE API access logs for unauthenticated POST/PUT requests that include file upload payloads, especially from external/untrusted sources ↗
- →Hot patches ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz and ise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz did NOT address CVE-2025-20282 (only fixed in ISE 3.4 Patch 2); devices running these hot patches remain vulnerable ↗
- ·CVE-2025-20282 only affects Cisco ISE and ISE-PIC Release 3.4; ISE 3.2 and earlier are NOT affected and do not require action ↗
- ·There are no workarounds available for CVE-2025-20282; the only remediation is upgrading to ISE 3.4 Patch 2 ↗
- ·Cisco's updated advisory clarified that the actively exploited flaws confirmed in July 2025 are CVE-2025-20281 and CVE-2025-20337, not CVE-2025-20282 specifically — though all three share the same advisory and patch ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8p2-wjjr-hr24: A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affe
ghsa_unreviewed·2025-06-26
CVE-2025-20282 [CRITICAL] CWE-269 GHSA-w8p2-wjjr-hr24: A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affe
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.
This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.
VulnCheck
Cisco Identity Services Engine Improper Privilege Management
vulncheck·2025·CVSS 10.0
CVE-2025-20282 [CRITICAL] Cisco Identity Services Engine Improper Privilege Management
Cisco Identity Services Engine Improper Privilege Management
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.
This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.
Affected: Cisco Identity Services Engine
Required Action: Apply remediations
Cisco
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
vendor_cisco·2025-06-25·CVSS 10.0
CVE-2025-20281 [CRITICAL] CWE-269 Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Note: Since the publication of version 1.0 of this advisory, improved fixed releases have become available. Cisco recommends upgrading to an enhanced fixed release as follows:
If Cisco ISE is running Release 3.4 Patch 2, no further action is necessary.
Cisco
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20282 Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
CVE-2025-20282: Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-269, CWE-74, CWE-269, CWE-74
Bug IDs: CSCwo99449, CSCwp02814, CSCwp02821, CSCwo99449, CSCwo99449
No detection rules found.
No public exploits indexed.
Checkpoint
28th July – Threat Intelligence Report
blogs_checkpoint·2025-07-28·CVSS 9.8
CVE-2025-53770 [CRITICAL] 28th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th July, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The US Energy Department, including its National Nuclear Security Administration (NNSA), was reportedly breached as part of a Microsoft SharePoint vulnerability exploit. The breach was linked to a broader espionage campaign, that targeted government agencies via the CVE-2025-53770 The extent of the intrusion and data compromise
Bleepingcomputer
Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
blogs_bleepingcomputer·2025-07-22·CVSS 10.0
[CRITICAL] Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
## Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
## Bill Toulas
Cisco is warning that three recently patched critical remote code execution vulnerabilities in Cisco Identity Services Engine (ISE) are now being actively exploited in attacks.
Although the vendor did not specify how they were being exploited and whether they were successful, applying the security updates as soon as possible is now critical.
“In July 2025, the Cisco PSIRT became aware of attempted exploitation of some of these vulnerabilities in the wild,” reads the updated advisory .
“Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate these vulnerabilities.”
Cisco Identity Services Engine (ISE) is a platform that enables large organizations to control n
Bleepingcomputer
Max severity Cisco ISE bug allows pre-auth command execution, patch now
blogs_bleepingcomputer·2025-07-17·CVSS 10.0
CVE-2025-20337 [CRITICAL] Max severity Cisco ISE bug allows pre-auth command execution, patch now
## Max severity Cisco ISE bug allows pre-auth command execution, patch now
## Bill Toulas
A critical vulnerability (CVE-2025-20337) in Cisco's Identity Services Engine (ISE) could be exploited to let an unauthenticated attacker store malicious files, execute arbitrary code, or gain root privileges on vulnerable devices.
The security issue received the maximum severity rating, 10 out of 10, and is caused by insufficient user-supplied input validation checks.
It was discovered by Kentaro Kawane, a researcher at the Japanese cybersecurity service GMO Cybersecurity by Ierae, and reported Trend Micro's Zero Day Initiative (ZDI).
A remote unauthenticated attacker could leverage it by submitting a specially crafted API request
The vulnerability was added via an update to the security bullet
Checkpoint
30th June – Threat Intelligence Report
blogs_checkpoint·2025-06-30
CVE-2025-20281 30th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Grocery giant Ahold Delhaize has disclosed a data breach that resulted in the theft of personal, financial, employment, and health information belonging to over 2.2 million individuals from its American business systems. The leaked data includes names, contact details, IDs, bank account numbers, and medical information . While
Bleepingcomputer
Cisco warns of max severity RCE flaws in Identity Services Engine
blogs_bleepingcomputer·2025-06-26·CVSS 10.0
CVE-2025-20281 [CRITICAL] Cisco warns of max severity RCE flaws in Identity Services Engine
## Cisco warns of max severity RCE flaws in Identity Services Engine
## Bill Toulas
Cisco has published a bulletin to warn about two critical, unauthenticated remote code execution (RCE) vulnerabilities affecting Cisco Identity Services Engine (ISE) and the Passive Identity Connector (ISE-PIC).
The flaws, tracked under CVE-2025-20281 and CVE-2025-20282 , are rated with max severity (CVSS score: 10.0). The first impacts ISE and ISE-PIC versions 3.4 and 3.3, while the second affects only version 3.4.
The root cause of CVE-2025-20281 is an insufficient validation of user-supplied input in a specific exposed API. This allows an unauthenticated, remote attacker to send a specially crafted API request to execute arbitrary operating system commands as the root user.
The second issue, CVE-202
Greynoiseio
NoiseLetter February 2026
blogs_greynoiseio
NoiseLetter February 2026
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
CTF
2025_BasmachAlpha / README
ctf_writeups·2025
2025_BasmachAlpha / README
# Bashmach Alpha Hanukkah Challenge - חידת בסמ"ח אלפא לחנוכה
## Riddle
Basmach Alpha released a short set of challenges for Hanukkah of 2025.
The challenges were advertised [here](https://www.ynet.co.il/digital/technews/article/hysvcdtf11l) and [here](https://www.idf.il/310925).
The official solution can be found [here](https://www.idf.il/%D7%90%D7%AA%D7%A8%D7%99-%D7%99%D7%97%D7%99%D7%93%D7%95%D7%AA/%D7%97%D7%98%D7%99%D7%91%D7%AA-%D7%91%D7%99%D7%A0%D7%94/2025/%D7%A8%D7%A7-95-%D7%90%D7%A0%D7%A9%D7%99%D7%9D-%D7%94%D7%A6%D7%9C%D7%99%D7%97%D7%95-%D7%9C%D7%A0%D7%A6%D7%97-%D7%90%D7%AA-%D7%97%D7%99%D7%93%D7%AA-%D7%91%D7%A1%D7%9E-%D7%97-%D7%A2%D7%9B%D7%A9%D7%99%D7%95-%D7%94%D7%A4%D7%AA%D7%A8%D7%95%D7%9F-%D7%A0%D7%97%D7%A9%D7%A3/).
> The Big Apple is where I reside,
> In the Roman empire, I take
2025-06-25
Published
Exploited in the wild