CVE-2025-20281: Cisco Identity Services Engine Injection Vulnerability
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.
Other sources
Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20281?
CVE-2025-20281 is a critical severity vulnerability that allows unauthenticated remote code execution on affected Cisco products.
How do I fix CVE-2025-20281?
To fix CVE-2025-20281, upgrade the affected Cisco Identity Services Engine or Cisco ISE-PIC to the latest patched versions as recommended by Cisco.
Who is affected by CVE-2025-20281?
CVE-2025-20281 affects users of Cisco Identity Services Engine and Cisco ISE-PIC, specifically those running unpatched versions.
What type of vulnerability is CVE-2025-20281?
CVE-2025-20281 is classified as a remote code execution vulnerability due to its ability to allow attackers to execute arbitrary code.
Can CVE-2025-20281 be exploited without authentication?
Yes, CVE-2025-20281 can be exploited by attackers without any required credentials, posing a significant security risk.