CVE-2025-20337 is a critical vulnerability in specific APIs of Cisco Identity Services Engine (ISE) and ISE-PIC, allowing unauthenticated, remote attackers to execute arbitrary code with root privileges due to insufficient input validation. This vulnerability carries a CVSS score of 10.0 (CRITICAL) due to its network-based attack vector, low complexity, and complete compromise potential (Confidentiality, Integrity, Availability). It is actively exploited in the wild, as confirmed by Cisco and Amazon Threat Intelligence, and has garnered significant community discussion and media coverage, despite no public Metasploit or ExploitDB modules being available. Organizations using affected Cisco ISE products should prioritize immediate patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:* | ||
3.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:* | ||
3.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:* | ||
3.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:* | ||
3.3.0CPE matchmatch criteria | cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.