Cisco Discloses '10' Flaw in ISE, ISE-PIC — Patch Now
ID: ff9b208c-4368-5cd8-865f-ae0cb21e6d46
STIX ID: report--ff9b208c-4368-5cd8-865f-ae0cb21e6d46
Feed Name: Dark Reading
Cisco disclosed a critical unauthenticated remote root RCE (CVE-2025-20337, CVSS 10) affecting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector, related to two other high-severity ISE vulnerabilities; Cisco recommends upgrading to 3.3 Patch 7 or 3.4 Patch 2 because prior hot patches do not address the new flaw. While Cisco reports no known active exploitation, public proof-of-concept exploits and scan traffic have been observed, and the flaws can be exploited without credentials via vulnerable APIs or file upload validation issues, so organizations should assess exposure and apply the provided updates promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
