logo

Max severity Cisco ISE bug allows pre-auth command execution, patch now

ID: f0ec6059-3a62-5df0-abfb-517a4961c03d

STIX ID: report--f0ec6059-3a62-5df0-abfb-517a4961c03d

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-07-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical set of unauthenticated RCE vulnerabilities (including CVE-2025-20337, CVE-2025-20281 and CVE-2025-20282) affecting Cisco Identity Services Engine (ISE) 3.3 and 3.4 have been disclosed; they received a maximum severity rating and can allow attackers to upload malicious files, execute arbitrary code, or obtain root privileges, and administrators are urged to apply the provided patches (3.3 Patch 7 or 3.4 Patch 2) immediately as no mitigations or workarounds exist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.