Critical unauthenticated remote code execution vulnerability in Cisco ISE API that allows attackers to execute arbitrary code as root. The vulnerability is actively exploited in the wild and requires no authentication or user interaction.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-07-16
Added to CISA KEV: 2025-07-28 12 DAYS BETWEEN CVE AND KEV
NVD - CVE-2025-20337Information Technology Laboratory National Vulnerability Database
Exploitation and Public Announcements In July 2025, the Cisco PSIRT became aware of attempted exploitation of CVE-2025-20281 and CVE-2025-20337 ...
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying ...
Cisco ISE RCE Vulnerability Exploited in Wild. The most severe vulnerabilities, CVE-2025-20281 and CVE-2025-20337, stem from insufficient validation of user-supplied input in specific APIs within ISE versions 3.3 and 3.4.
The vulnerabilities, tracked as CVE-2025-20281 and CVE-2025-20337, allow attackers to achieve remote code execution with root privileges on affected systems. Key Takeaways 1. CISA added two Cisco ISE vulnerabilities (CVE-2025-20281, CVE-2025-20337) to its Known Exploited...