logo

Cisco Warns of Credential Vuln on AWS, Azure, Oracle Cloud

ID: b8f0fd51-3cf8-52c6-b66b-bbba2711f7e3

STIX ID: report--b8f0fd51-3cf8-52c6-b66b-bbba2711f7e3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-06-05

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

A critical vulnerability (CVE-2025-20286, CVSS 9.9) in Cisco Identity Services Engine (ISE) cloud deployments on AWS, Microsoft Azure, and Oracle Cloud Infrastructure causes identical credentials to be generated across deployments of the same release and platform, potentially allowing remote actors to access sensitive data, modify configurations, or disrupt services; a proof-of-concept exists but there is no evidence of in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.