Critical Zero-Day Flaws Allow Complete Takeover of Cisco Identity Services Engine Systems


# Cisco Warns of Critical Security Flaws in Identity Services Engine

Cisco has issued an urgent security bulletin alerting users to two critical vulnerabilities in its Identity Services Engine (ISE) and Passive Identity Connector (ISE-PIC) platforms. Both flaws carry the maximum severity rating of 10.0 on the CVSS scale and allow unauthenticated remote code execution.

## Critical Vulnerabilities Discovered

The two security flaws, designated CVE-2025-20281 and CVE-2025-20282, pose severe risks to organizations using Cisco’s network security platforms:

**CVE-2025-20281** affects ISE and ISE-PIC versions 3.4 and 3.3. The vulnerability stems from inadequate input validation in an exposed API, enabling attackers to send malicious requests that execute arbitrary commands with root privileges.

**CVE-2025-20282** impacts only version 3.4 and involves poor file validation in an internal API. This flaw allows attackers to upload and execute malicious files in privileged system directories with root access.

## High-Value Targets at Risk

Cisco ISE serves as a critical network security component for large enterprises, government agencies, universities, and service providers. The platform manages network access control, identity verification, and policy enforcement across organizational networks.

Given ISE’s central role in enterprise security infrastructure, successful exploitation of these vulnerabilities could result in complete system compromise and full remote control of affected devices.

## Immediate Action Required

Cisco reports no known active exploitation of these vulnerabilities but emphasizes the urgent need for updates. The company has released patches to address both flaws:

– **Version 3.3 users**: Upgrade to Patch 6 (ise-apply-CSCwo99449_3.3.0.430_patch4)
– **Version 3.4 users**: Upgrade to Patch 2 (ise-apply-CSCwo99449_3.4.0.608_patch1)

No workarounds are available, making immediate patching the only effective mitigation strategy.

## Additional Security Concern

Cisco also disclosed a separate medium-severity authentication bypass vulnerability (CVE-2025-20264) affecting all ISE versions up to 3.4. This flaw involves inadequate authorization enforcement for SAML SSO users, potentially allowing authenticated attackers to modify system settings or restart systems.

Fixes are available in version 3.4 Patch 2 and 3.3 Patch 5, with additional patches planned for older versions. Users of unsupported ISE 3.1 and earlier versions should migrate to newer releases.

## Conclusion

These critical vulnerabilities highlight the importance of maintaining current security patches for network infrastructure components. Organizations using Cisco ISE should prioritize immediate patching to prevent potential system compromise and maintain network security integrity.

Share This Article