CVE-2025-20124 is a critical vulnerability in Cisco Identity Services Engine (ISE) that allows an authenticated, remote attacker with read-only administrative credentials to execute arbitrary commands as the root user. This is due to insecure deserialization of user-supplied Java byte streams. The vulnerability has a CVSS score of 7.2 (High) and a FAUCET Risk Score of 95/100, indicating a significant impact including potential for full compromise and privilege escalation. While not yet in the KEV catalog, an ExploitDB entry (EDB-52396) exists, and there is notable community discussion and media coverage, suggesting active interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.