cbcvebase.
CVE-2025-20282
published 2025-06-25

CVE-2025-20282: A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected…

PriorityP196critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
9.80%
95.0th percentile
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscoidentity_services_engine
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_unauthenticated

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-20282 affects only Cisco ISE and ISE-PIC Release 3.4; exploit involves uploading arbitrary files via an internal API to privileged directories and executing them as root — monitor for unexpected file writes to privileged directories on ISE appliances
  • Active exploitation of CVE-2025-20282 (alongside CVE-2025-20281 and CVE-2025-20337) was confirmed in July 2025; treat any anomalous unauthenticated requests to Cisco ISE internal APIs as high-priority alerts
  • The vulnerability is triggered via an unauthenticated request to an internal API endpoint; monitor ISE API access logs for unauthenticated POST/PUT requests that include file upload payloads, especially from external/untrusted sources
  • Hot patches ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz and ise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz did NOT address CVE-2025-20282 (only fixed in ISE 3.4 Patch 2); devices running these hot patches remain vulnerable
  • ·CVE-2025-20282 only affects Cisco ISE and ISE-PIC Release 3.4; ISE 3.2 and earlier are NOT affected and do not require action
  • ·There are no workarounds available for CVE-2025-20282; the only remediation is upgrading to ISE 3.4 Patch 2
  • ·Cisco's updated advisory clarified that the actively exploited flaws confirmed in July 2025 are CVE-2025-20281 and CVE-2025-20337, not CVE-2025-20282 specifically — though all three share the same advisory and patch

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.