logo

Cisco patches critical CVE-2025-20337 bug in Identity Services Engine with CVSS 10 Severity

ID: d314b63a-50c9-5da6-9595-946e92bd90df

STIX ID: report--d314b63a-50c9-5da6-9595-946e92bd90df

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2025-07-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Cisco patched CVE-2025-20337, a critical (CVSS 10) unauthenticated remote code execution vulnerability in Identity Services Engine (ISE) and ISE-PIC that can allow an attacker to execute arbitrary code as root; Cisco advises upgrading to specified fixed releases (3.3 Patch 7 or 3.4 Patch 2) and warns that certain hotpatches do not mitigate the issue. The advisory links the flaw to prior similar CVE-2025-20281, lists affected versions and fixes, and states there is no known exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.