CVE-2025-20281
Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
CVE-2025-20281 is a remote code execution vulnerability affecting Cisco Identity Services Engine (ISE). The vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the remote host as the root user due to insufficient validation of user-supplied input.
Exploiting this vulnerability can allow an attacker to gain complete control over the affected system. This includes accessing sensitive data, modifying or deleting system resources, and potentially installing malware or creating backdoors.
Mitigations
- Apply the relevant patches as mentioned in the vendor advisory.
Rapid Response N-Day Testing
