Cisco patches critical CVE-2025-20337 bug in Identity Services Engine with CVSS 10 Severity
ID: d314b63a-50c9-5da6-9595-946e92bd90df
STIX ID: report--d314b63a-50c9-5da6-9595-946e92bd90df
Feed Name: Security Affairs
Cisco patched CVE-2025-20337, a critical (CVSS 10) unauthenticated remote code execution vulnerability in Identity Services Engine (ISE) and ISE-PIC that can allow an attacker to execute arbitrary code as root; Cisco advises upgrading to specified fixed releases (3.3 Patch 7 or 3.4 Patch 2) and warns that certain hotpatches do not mitigate the issue. The advisory links the flaw to prior similar CVE-2025-20281, lists affected versions and fixes, and states there is no known exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
