CVE-2025-20125 is a critical authorization bypass vulnerability in Cisco Identity Services Engine (ISE) that allows authenticated, remote attackers with read-only credentials to gain elevated privileges. This flaw, rated 7.2 HIGH, stems from improper authorization and data validation in a specific API, enabling attackers to obtain sensitive information, modify configurations, and restart the device. While requiring valid read-only administrative credentials, its impact is significant, potentially disrupting network authentication services. Although not currently in CISA's KEV catalog, public exploit code exists (EDB-52397), and it has garnered substantial community discussion and media coverage, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.