CVE-2025-20337
published 2025-07-16CVE-2025-20337: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying…
PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-08-18
Exploited in the wild
EPSS
65.10%
99.2th percentile
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_identity_services_engine_software | — | — |
| cisco | cisco_ise_passive_identity_connector | — | — |
| cisco | cisco_ise_passive_identity_connector | — | — |
| cisco | cisco_ise_passive_identity_connector | — | — |
| cisco | cisco_ise_passive_identity_connector | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_passive_identity_connector | — | — |
| cisco | identity_services_engine_unauthenticated | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is exploited via a crafted API request targeting a specific API endpoint in Cisco ISE/ISE-PIC. Monitor for anomalous unauthenticated API requests to ISE endpoints, particularly those containing serialized Java payloads. ↗
- →The deployed web shell 'IdentityAuditAction' registered as an HTTP listener to intercept all requests and used Java reflection to inject into Tomcat server threads. Hunt for unexpected HTTP listeners and anomalous Tomcat thread injections on ISE hosts. ↗
- →The web shell used DES encryption with non-standard base64 encoding for C2 communications and required knowledge of specific HTTP headers to access. Look for unusual HTTP headers in requests to ISE and DES-encrypted/non-standard base64 traffic. ↗
- →The exploit chain includes a Linux container escape from a privileged Docker container using cgroups and release_agent. Monitor for cgroup release_agent manipulation on ISE host systems. ↗
- →Attackers used ${IFS} to bypass argument tokenization in Java's Runtime.exec(). Inspect API request payloads for ${IFS} usage as a command injection bypass indicator. ↗
- →Amazon MadPot honeypot data detected exploitation of CVE-2025-20337 targeting a previously undocumented endpoint in Cisco ISE using vulnerable deserialization logic, prior to public disclosure. Audit ISE access logs for requests to undocumented/unexpected API endpoints. ↗
- →Attackers leveraged CVE-2025-20337 to gain pre-auth admin access to Cisco ISE endpoints. Alert on any unauthenticated sessions achieving administrative-level access on ISE. ↗
- ·Only ISE versions 3.3 and 3.4 are affected. ISE 3.2 and earlier are NOT vulnerable and do not require action. ↗
- ·The hot patches (ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz and ise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz) did NOT address CVE-2025-20337 and have been deferred. Full patches (ISE 3.3 Patch 7 / ISE 3.4 Patch 2) are required. ↗
- ·There are no workarounds available for CVE-2025-20337; patching is the only remediation. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Cisco Identity Services Engine Injection Vulnerability
cisa·2025-07-28·CVSS 10.0
CVE-2025-20337 [CRITICAL] CWE-74 Cisco Identity Services Engine Injection Vulnerability
Vulnerability: Cisco Identity Services Engine Injection Vulnerability
Affected: Cisco Identity Services Engine
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZA
Cisco
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
vendor_cisco·2025-06-25·CVSS 10.0
CVE-2025-20281 [CRITICAL] CWE-269 Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Note: Since the publication of version 1.0 of this advisory, improved fixed releases have become available. Cisco recommends upgrading to an enhanced fixed release as follows:
If Cisco ISE is running Release 3.4 Patch 2, no further action is necessary.
Cisco
Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20337 Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
CVE-2025-20337: Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-269, CWE-74, CWE-269, CWE-74
Bug IDs: CSCwo99449, CSCwp02814, CSCwp02821, CSCwo99449, CSCwo99449
GHSA
GHSA-p9cx-6464-94g4: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde
ghsa_unreviewed·2025-07-16
CVE-2025-20337 [CRITICAL] CWE-74 GHSA-p9cx-6464-94g4: A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the unde
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.
VulnCheck
Cisco Identity Services Engine Injection Vulnerability
vulncheck·2025·CVSS 10.0
CVE-2025-20337 [CRITICAL] CWE-74 Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine Injection Vulnerability
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
Affected: Cisco Identity Services Engine
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rc
Suricata
ET WEB_SPECIFIC_APPS Cisco ISE StrongSwan API Unauthenticated Remote Code Execution (CVE-2025-20337)
suricata·2025-11-14·CVSS 10.0
CVE-2025-20337 [CRITICAL] ET WEB_SPECIFIC_APPS Cisco ISE StrongSwan API Unauthenticated Remote Code Execution (CVE-2025-20337)
ET WEB_SPECIFIC_APPS Cisco ISE StrongSwan API Unauthenticated Remote Code Execution (CVE-2025-20337)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Cisco ISE StrongSwan API Unauthenticated Remote Code Execution (CVE-2025-20337)"; flow:established,to_server; http.uri; content:"/api/v1/strongswan/tunnel"; fast_pattern; http.request_body; content:"|22|tunnel_config|22 3a|"; pcre:"/^\s*\x22(?:[A-Za-z0-9\x2b\x2f\x3d]|\x25(?:2[bBfF]|3[dD]))+/R"; http.method; content:"POST"; reference:url,github.com/B1ack4sh/Blackash-CVE-2025-20337/blob/main/CVE-2025-20337.yaml; reference:cve,2025-20337; classtype:web-application-attack; sid:2065769; rev:1; metadata:affected_product Cisco_ISE, attack_target Server, tls_state TLSDecrypt, created_at 2025_11_14, cve CVE_2025_20337, deployment
No public exploits indexed.
Bleepingcomputer
Cisco warns of Identity Service Engine flaw with exploit code
blogs_bleepingcomputer·2026-01-08·CVSS 4.9
CVE-2026-20029 [MEDIUM] Cisco warns of Identity Service Engine flaw with exploit code
## Cisco warns of Identity Service Engine flaw with exploit code
## Sergiu Gatlan
Cisco has patched a vulnerability in its Identity Services Engine (ISE) network access control solution, with public proof-of-concept exploit code, that can be abused by attackers with admin privileges.
Enterprise admins use Cisco ISE to manage endpoint, user, and device access to network resources while enforcing a zero-trust architecture.
The security flaw ( CVE-2026-20029 ) affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) regardless of device configuration, and remote attackers with high privileges can exploit it to access sensitive information on unpatched devices.
"This vulnerability is due to improper parsing of XML that is processed by the web-based m
Wiz
Supply Chain Attacks & AI Vulnerabilities: December Cloud Security Update | Wiz
blogs_wiz·2025-12-01·CVSS 10.0
[CRITICAL] Supply Chain Attacks & AI Vulnerabilities: December Cloud Security Update | Wiz
Welcome back! This edition delivers the latest cloud security highlights: key breaches, unique data findings, and must-watch vulnerabilities. Let’s jump in.
🔍 Highlights
Shai-Hulud 2.0: Ongoing Supply Chain Campaign Referencing Shai-Hulud
A new npm supply-chain campaign referencing Shai-Hulud temporarily compromised packages from Zapier, ENS Domains, PostHog, Postman, and others. This wave leveraged temporarily compromised npm maintainer accounts to publish trojanized versions of legitimate packages from major ecosystems. Wiz observed over 25,000 repositories containing secrets across ~350 unique users.
The malicious packages execute code during the preinstall phase, enabling theft of developer and CI/CD secrets and automated propagation to new repositories. Exfiltration is conducted c
Checkpoint
17th November – Threat Intelligence Report
blogs_checkpoint·2025-11-17·CVSS 9.8
CVE-2025-61882 [CRITICAL] 17th November – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th November – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th November, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Cl0p’s Oracle E-Business Suite (CVE-2025-61882) zero-day campaign continues to expand. There are new confirmed breaches at The Washington Post, Logitech, Allianz UK, and GlobalLogic, as well as a newly listed but unconfirmed breach involving the British National Health Service (NHS). The group has leaked data sets rangi
Bleepingcomputer
Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
blogs_bleepingcomputer·2025-11-12·CVSS 10.0
CVE-2025-5777 [CRITICAL] Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
## Hackers exploited Citrix, Cisco ISE flaws in zero-day attacks
## Bill Toulas
An advanced threat actor exploited the critical vulnerabilities “Citrix Bleed 2" (CVE-2025-5777) in NetScaler ADC and Gateway, and CVE-2025-20337 affecting Cisco Identity Service Engine (ISE) as zero-days to deploy custom malware.
Amazon’s threat intelligence team, analyzing “ MadPot ” honeypot data, found that hackers leveraged the two security issues before the security issues were disclosed publicly and patches became available.
“Our Amazon MadPot honeypot service detected exploitation attempts for the Citrix Bleed Two vulnerability ( CVE-2025-5777 ) prior to public disclosure, indicating a threat actor had been exploiting the vulnerability as a zero-day,” explains Amazon .
“Through further investigatio
Bleepingcomputer
Exploit available for critical Cisco ISE bug exploited in attacks
blogs_bleepingcomputer·2025-07-28·CVSS 10.0
CVE-2025-20281 [CRITICAL] Exploit available for critical Cisco ISE bug exploited in attacks
## Exploit available for critical Cisco ISE bug exploited in attacks
## Bill Toulas
Security researcher Bobby Gould has published a blog post demonstrating a complete exploit chain for CVE-2025-20281, an unauthenticated remote code execution vulnerability in Cisco Identity Services Engine (ISE).
The critical vulnerability was first disclosed on June 25, 2025 , with Cisco warning that it impacts ISE and ISE-PIC versions 3.3 and 3.4, allowing unauthenticated, remote attackers to upload arbitrary files to the target system and execute them with root privileges.
The issue stems from unsafe deserialization and command injection in the enableStrongSwanTunnel() method.
Three weeks later, the vendor added one more flaw to the same bulletin, CVE-2025-20337 , which relates to the same flaw but
Checkpoint
28th July – Threat Intelligence Report
blogs_checkpoint·2025-07-28·CVSS 9.8
CVE-2025-53770 [CRITICAL] 28th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 28th July, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The US Energy Department, including its National Nuclear Security Administration (NNSA), was reportedly breached as part of a Microsoft SharePoint vulnerability exploit. The breach was linked to a broader espionage campaign, that targeted government agencies via the CVE-2025-53770 The extent of the intrusion and data compromise
Bleepingcomputer
Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
blogs_bleepingcomputer·2025-07-22·CVSS 10.0
[CRITICAL] Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
## Cisco: Maximum-severity ISE RCE flaws now exploited in attacks
## Bill Toulas
Cisco is warning that three recently patched critical remote code execution vulnerabilities in Cisco Identity Services Engine (ISE) are now being actively exploited in attacks.
Although the vendor did not specify how they were being exploited and whether they were successful, applying the security updates as soon as possible is now critical.
“In July 2025, the Cisco PSIRT became aware of attempted exploitation of some of these vulnerabilities in the wild,” reads the updated advisory .
“Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate these vulnerabilities.”
Cisco Identity Services Engine (ISE) is a platform that enables large organizations to control n
Bleepingcomputer
Max severity Cisco ISE bug allows pre-auth command execution, patch now
blogs_bleepingcomputer·2025-07-17·CVSS 10.0
CVE-2025-20337 [CRITICAL] Max severity Cisco ISE bug allows pre-auth command execution, patch now
## Max severity Cisco ISE bug allows pre-auth command execution, patch now
## Bill Toulas
A critical vulnerability (CVE-2025-20337) in Cisco's Identity Services Engine (ISE) could be exploited to let an unauthenticated attacker store malicious files, execute arbitrary code, or gain root privileges on vulnerable devices.
The security issue received the maximum severity rating, 10 out of 10, and is caused by insufficient user-supplied input validation checks.
It was discovered by Kentaro Kawane, a researcher at the Japanese cybersecurity service GMO Cybersecurity by Ierae, and reported Trend Micro's Zero Day Initiative (ZDI).
A remote unauthenticated attacker could leverage it by submitting a specially crafted API request
The vulnerability was added via an update to the security bullet
Greynoiseio
NoiseLetter August 2025
blogs_greynoiseio
NoiseLetter August 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2025-07-16
Published
2025-07-28
Added to CISA KEV
Exploited in the wild