cbcvebase.
CVE-2025-20337
published 2025-07-16

CVE-2025-20337: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying…

critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEV
CISA Known Exploited Vulnerabilitydue 2025-08-18
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

Affected

18 ranges
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_ise_passive_identity_connector
ciscocisco_ise_passive_identity_connector
ciscocisco_ise_passive_identity_connector
ciscocisco_ise_passive_identity_connector
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_unauthenticated

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL