CVE-2025-20286: ISE on AWS Static Credential
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20286?
CVE-2025-20286 is rated as a critical vulnerability due to its potential to allow unauthorized access to sensitive data.
How do I fix CVE-2025-20286?
To fix CVE-2025-20286, update your Cisco Identity Services Engine (ISE) to the latest patched version provided by Cisco.
Who is affected by CVE-2025-20286?
CVE-2025-20286 affects cloud deployments of Cisco Identity Services Engine (ISE) specifically on AWS, Microsoft Azure, and Oracle Cloud Infrastructure (OCI).
Can CVE-2025-20286 be exploited remotely?
Yes, CVE-2025-20286 can be exploited by an unauthenticated remote attacker.
What type of data can an attacker access through CVE-2025-20286?
An attacker can access sensitive data and execute limited administrative operations as a result of CVE-2025-20286.