Max severity Cisco ISE bug allows pre-auth command execution, patch now
ID: f0ec6059-3a62-5df0-abfb-517a4961c03d
STIX ID: report--f0ec6059-3a62-5df0-abfb-517a4961c03d
Feed Name: Bleeping Computer
Threat Score
A critical set of unauthenticated RCE vulnerabilities (including CVE-2025-20337, CVE-2025-20281 and CVE-2025-20282) affecting Cisco Identity Services Engine (ISE) 3.3 and 3.4 have been disclosed; they received a maximum severity rating and can allow attackers to upload malicious files, execute arbitrary code, or obtain root privileges, and administrators are urged to apply the provided patches (3.3 Patch 7 or 3.4 Patch 2) immediately as no mitigations or workarounds exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
