Vulnerability record · CVE-2025-20281 · published 25 June 2025
CVE-2025-20281: Cisco ISE API unauthenticated remote code execution
Cisco · Identity Services Engine
Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating system. Because the flaw is reachable without credentials and yields root, it is a full compromise of the appliance.
Description
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable root code execution with CVSS 10, KEV listing and near-certain EPSS probability makes this an urgent patch.
What it is
Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating system. Because the flaw is reachable without credentials and yields root, it is a full compromise of the appliance.
Impact
An unauthenticated remote attacker gains root-level code execution on the ISE or ISE-PIC host, giving control of the appliance and any identity data or trust relationships it holds.
Attack surface
Reached over the network via a crafted API request; the CVSS vector shows PR:N and UI:N, so no authentication or user interaction is required.
Exploitation
CVE-2025-20281 is listed in CISA KEV with a 2025-08-18 remediation due date, and a third-party advisory carries an Exploit tag; EPSS 30-day probability is 0.9723. No ransomware campaign use is documented.
What to do
- Apply the Cisco security advisory fix for ISE and ISE-PIC immediately; this is a KEV-listed flaw with a federal due date.
- If patching cannot be completed at once, restrict network access to the affected API to trusted management networks only.
- Audit and disable any unnecessary external exposure of ISE management and API interfaces.
- After patching, rotate credentials and review the appliance for signs of tampering, since root access may have been obtained.
- Track BOD 22-01 guidance and confirm remediation status against the KEV due date.
Detection
- Review ISE API and web access logs for crafted or anomalous requests to the affected API endpoint, especially from unexpected source addresses.
- Monitor for unexpected processes, child processes of web/API services, or new files on the ISE host that indicate command execution.
- Alert on outbound connections from ISE appliances to unfamiliar hosts, which may indicate post-exploitation activity.
- Correlate authentication and configuration changes on ISE with API request logs to spot unauthorized administrative activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-20281 to the Known Exploited Vulnerabilities catalog on 28 July 2025 as "Cisco Identity Services Engine Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 August 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2025-20281 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-20281), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.