cbcvebase.
CVE-2025-20286
published 2025-06-04

CVE-2025-20286: A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE)…

PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.05%
60.2th percentile
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for access attempts to Cisco ISE cloud deployments (AWS, Azure, OCI) originating from unexpected external IPs, particularly targeting administrative interfaces over unsecured ports — indicative of static credential reuse across deployments.
  • Scope detection to Cisco ISE instances where the Primary Administration Node (PAN) is deployed in a cloud environment (AWS, Azure, or OCI); on-premises PAN deployments are not affected and should be excluded from alerting.
  • Proof-of-concept exploit code is publicly available for CVE-2025-20286; prioritize detection and patching for cloud-deployed ISE Primary Administration Nodes as active exploitation is more likely.
  • Alert on unauthenticated or anomalous administrative logins to Cisco ISE cloud nodes, especially successful authentications that do not correlate with known admin activity — static shared credentials mean any cloud-deployed ISE instance of the same release/platform is a valid target.
  • ·The 'application reset-config ise' command resets Cisco ISE to factory configuration AND resets user passwords; restoring from backup will also restore the original (vulnerable) static credentials — ensure new credentials are set after any restore.
  • ·The following ISE deployment types are NOT vulnerable and should be excluded from remediation scope: all on-premises deployments (ISO/OVA from Cisco Software Download Center), ISE on Azure VMware Solution (AVS), ISE on Google Cloud VMware Engine, ISE on VMware cloud in AWS, and ISE hybrid deployments with all ISE Administrator personas (Primary and Secondary Administration) on-premises.
  • ·There are no workarounds that address this vulnerability; the only remediation is applying Cisco's released software updates or running the password-reset command as a temporary mitigation.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.9CRITICAL
vendor_msrc2.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.