Vulnerability record · CVE-2025-20337 · published 16 July 2025
CVE-2025-20337: Cisco ISE API input validation flaw allows unauthenticated root RCE
Cisco · Identity Services Engine
Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary code as root on the underlying operating system. Because no credentials are needed and the impact is full system compromise, this is a severe pre-auth flaw in a security-critical identity platform.
Description
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote root code execution with a CVSS score of 10 and confirmed KEV listing makes this an urgent patch-first issue.
What it is
Cisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary code as root on the underlying operating system. Because no credentials are needed and the impact is full system compromise, this is a severe pre-auth flaw in a security-critical identity platform.
Impact
An attacker gains root-level code execution on the affected appliance, allowing full control of the device and any identity data or credentials it processes.
Attack surface
Reachable over the network through a crafted API request; the CVSS vector shows no privileges required and no user interaction, so the API endpoint is exposed to unauthenticated remote callers.
Exploitation
CVE-2025-20337 is listed in CISA KEV with a 2025-08-18 remediation due date, and EPSS gives a 30-day probability of 0.676 (99.3rd percentile), indicating active exploitation is expected or observed.
What to do
- Apply the Cisco security advisory patch for ISE and ISE-PIC immediately.
- If patching is not possible, restrict network access to the affected API to trusted management networks only.
- Follow CISA BOD 22-01 guidance and the KEV required action, including discontinuing use if no mitigation exists.
- Audit ISE API exposure and remove any internet-facing or unnecessary external access.
- Monitor Cisco advisory updates for revised fixed versions or workarounds.
Detection
- Review ISE and ISE-PIC API logs for anomalous or malformed requests, especially from unexpected source IPs.
- Alert on unexpected root-level process creation or command execution on ISE appliances.
- Monitor for outbound connections from ISE hosts to unknown external addresses.
- Correlate authentication and API access logs for requests that bypass normal credential checks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-20337 to the Known Exploited Vulnerabilities catalog on 28 July 2025 as "Cisco Identity Services Engine Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 18 August 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-20337 | US Government Resource |
Track CVE-2025-20337 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-20337), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.