cbcvebase.
CVE-2025-20337
published 2025-07-16

CVE-2025-20337: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-08-18
Exploited in the wild
EPSS
65.10%
99.2th percentile
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

Affected

18 ranges
VendorProductVersion rangeFixed in
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_identity_services_engine_software
ciscocisco_ise_passive_identity_connector
ciscocisco_ise_passive_identity_connector
ciscocisco_ise_passive_identity_connector
ciscocisco_ise_passive_identity_connector
ciscoidentity_services_engine
ciscoidentity_services_engine
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_passive_identity_connector
ciscoidentity_services_engine_unauthenticated

Detection & IOCsextracted from sources · hover to see the quote

filenameise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz
filenameise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz
  • The vulnerability is exploited via a crafted API request targeting a specific API endpoint in Cisco ISE/ISE-PIC. Monitor for anomalous unauthenticated API requests to ISE endpoints, particularly those containing serialized Java payloads.
  • The deployed web shell 'IdentityAuditAction' registered as an HTTP listener to intercept all requests and used Java reflection to inject into Tomcat server threads. Hunt for unexpected HTTP listeners and anomalous Tomcat thread injections on ISE hosts.
  • The web shell used DES encryption with non-standard base64 encoding for C2 communications and required knowledge of specific HTTP headers to access. Look for unusual HTTP headers in requests to ISE and DES-encrypted/non-standard base64 traffic.
  • The exploit chain includes a Linux container escape from a privileged Docker container using cgroups and release_agent. Monitor for cgroup release_agent manipulation on ISE host systems.
  • Attackers used ${IFS} to bypass argument tokenization in Java's Runtime.exec(). Inspect API request payloads for ${IFS} usage as a command injection bypass indicator.
  • Amazon MadPot honeypot data detected exploitation of CVE-2025-20337 targeting a previously undocumented endpoint in Cisco ISE using vulnerable deserialization logic, prior to public disclosure. Audit ISE access logs for requests to undocumented/unexpected API endpoints.
  • Attackers leveraged CVE-2025-20337 to gain pre-auth admin access to Cisco ISE endpoints. Alert on any unauthenticated sessions achieving administrative-level access on ISE.
  • ·Only ISE versions 3.3 and 3.4 are affected. ISE 3.2 and earlier are NOT vulnerable and do not require action.
  • ·The hot patches (ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz and ise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz) did NOT address CVE-2025-20337 and have been deferred. Full patches (ISE 3.3 Patch 7 / ISE 3.4 Patch 2) are required.
  • ·There are no workarounds available for CVE-2025-20337; patching is the only remediation.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.