CVE-2025-20286
published 2025-06-04CVE-2025-20286: A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE)…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.05%
60.2th percentile
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.
This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.
Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for access attempts to Cisco ISE cloud deployments (AWS, Azure, OCI) originating from unexpected external IPs, particularly targeting administrative interfaces over unsecured ports — indicative of static credential reuse across deployments. ↗
- →Scope detection to Cisco ISE instances where the Primary Administration Node (PAN) is deployed in a cloud environment (AWS, Azure, or OCI); on-premises PAN deployments are not affected and should be excluded from alerting. ↗
- →Proof-of-concept exploit code is publicly available for CVE-2025-20286; prioritize detection and patching for cloud-deployed ISE Primary Administration Nodes as active exploitation is more likely. ↗
- →Alert on unauthenticated or anomalous administrative logins to Cisco ISE cloud nodes, especially successful authentications that do not correlate with known admin activity — static shared credentials mean any cloud-deployed ISE instance of the same release/platform is a valid target. ↗
- ·The 'application reset-config ise' command resets Cisco ISE to factory configuration AND resets user passwords; restoring from backup will also restore the original (vulnerable) static credentials — ensure new credentials are set after any restore. ↗
- ·The following ISE deployment types are NOT vulnerable and should be excluded from remediation scope: all on-premises deployments (ISO/OVA from Cisco Software Download Center), ISE on Azure VMware Solution (AVS), ISE on Google Cloud VMware Engine, ISE on VMware cloud in AWS, and ISE hybrid deployments with all ISE Administrator personas (Primary and Secondary Administration) on-premises. ↗
- ·There are no workarounds that address this vulnerability; the only remediation is applying Cisco's released software updates or running the password-reset command as a temporary mitigation. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.9CRITICAL
vendor_msrc2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
vendor_cisco·2025-06-04·CVSS 9.9
CVE-2025-20286 [CRITICAL] CWE-259 Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.
This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this
Microsoft
A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
vendor_msrc·2021-03-09·CVSS 2.7
CVE-2021-20286 [LOW] CWE-617 A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Requir
Cisco
Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20286 Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
CVE-2025-20286: Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker coul
GHSA
GHSA-mj8j-c9rh-x2c6: A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engi
ghsa_unreviewed·2025-06-04
CVE-2025-20286 [CRITICAL] CWE-259 GHSA-mj8j-c9rh-x2c6: A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engi
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.
This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed i
No detection rules found.
No public exploits indexed.
Checkpoint
9th June – Threat Intelligence Report
blogs_checkpoint·2025-06-09
CVE-2025-49113 9th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 9th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th June, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
American tax company, Optima Tax Relief, has disclosed a ransomware attack that resulted in the theft of 69GB of sensitive data, including corporate records and customer case files containing personal information such as Social Security numbers, phone numbers, and home addresses. The attack impacted the company’s servers in a dou
Bleepingcomputer
Cisco warns of ISE and CCP flaws with public exploit code
blogs_bleepingcomputer·2025-06-04·CVSS 9.9
CVE-2025-20286 [CRITICAL] Cisco warns of ISE and CCP flaws with public exploit code
## Cisco warns of ISE and CCP flaws with public exploit code
## Sergiu Gatlan
Cisco has released patches to address three vulnerabilities with public exploit code in its Identity Services Engine (ISE) and Customer Collaboration Platform (CCP) solutions.
The most severe of the three is a critical static credential vulnerability tracked as CVE-2025-20286 , found by GMO Cybersecurity's Kentaro Kawane in Cisco ISE. This identity-based policy enforcement software provides endpoint access control and network device administration in enterprise environments.
The vulnerability is due to improperly generated credentials when deploying Cisco ISE on cloud platforms, resulting in shared credentials across different deployments.
Unauthenticated attackers can exploit it by extracting user credentia
2025-06-04
Published