← Vulnerability feed

Vulnerability record · CVE-2025-20337 · published 16 July 2025

CVE-2025-20337: Cisco ISE API input validation flaw allows unauthenticated root RCE

Cisco · Identity Services Engine

Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary code as root on the underlying operating system. Because no credentials are needed and the impact is full system compromise, this is a severe pre-auth flaw in a security-critical identity platform.

10.0 CVSS 3.1 Critical CISA KEV since 28 Jul 2025 EPSS 68% · top 0.7% CWE-74 · Injection
10.0CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated remote root code execution with a CVSS score of 10 and confirmed KEV listing makes this an urgent patch-first issue.

What it is

Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary code as root on the underlying operating system. Because no credentials are needed and the impact is full system compromise, this is a severe pre-auth flaw in a security-critical identity platform.

Impact

An attacker gains root-level code execution on the affected appliance, allowing full control of the device and any identity data or credentials it processes.

Attack surface

Reachable over the network through a crafted API request; the CVSS vector shows no privileges required and no user interaction, so the API endpoint is exposed to unauthenticated remote callers.

Exploitation

CVE-2025-20337 is listed in CISA KEV with a 2025-08-18 remediation due date, and EPSS gives a 30-day probability of 0.676 (99.3rd percentile), indicating active exploitation is expected or observed.

What to do

  • Apply the Cisco security advisory patch for ISE and ISE-PIC immediately.
  • If patching is not possible, restrict network access to the affected API to trusted management networks only.
  • Follow CISA BOD 22-01 guidance and the KEV required action, including discontinuing use if no mitigation exists.
  • Audit ISE API exposure and remove any internet-facing or unnecessary external access.
  • Monitor Cisco advisory updates for revised fixed versions or workarounds.

Detection

  • Review ISE and ISE-PIC API logs for anomalous or malformed requests, especially from unexpected source IPs.
  • Alert on unexpected root-level process creation or command execution on ISE appliances.
  • Monitor for outbound connections from ISE hosts to unknown external addresses.
  • Correlate authentication and API access logs for requests that bypass normal credential checks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-20337 to the Known Exploited Vulnerabilities catalog on 28 July 2025 as "Cisco Identity Services Engine Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 August 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-20337 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-76460Cisco ISE API authentication bypass via insufficient access controlCisco Identity Services Engine contains an authentication bypass in an API endpoint caused by insufficient authentication control. An unauthenticated…KEVEPSS 14%analysed10.0CVE-2025-20281Cisco ISE API unauthenticated remote code executionCisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, allowing a crafted request to reach the underlying operating s…KEVEPSS 98%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed10.0CVE-2025-20282Cisco identity services engine improper privilege management vulnerabilityA vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff…EPSS 39%10.0CVE-2011-3290Cisco identity services engine vulnerabilityCisco Identity Services Engine (ISE) before 1.0.4.MR2 has default Oracle database credentials, which allows remote attackers to modify settings or pe…EPSS 2.3%9.9CVE-2026-20180Cisco identity services engine path traversal vulnerabilityA vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…EPSS 6.0%9.9CVE-2026-20186Cisco identity services engine command injection vulnerabilityA vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…EPSS 5.6%9.9CVE-2026-20147Cisco identity services engine passive identity connector command injection vulnerabilityA vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2025-20337), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.