Maximum-Severity Cisco ISE Vulnerabilities Grant Attackers Instant Root Access Without Authentication


# Cisco Releases Critical Security Updates for Identity Services Engine

Cisco has issued urgent security patches to fix two critical vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) products. Both flaws received the maximum severity rating of 10.0 on the CVSS scale, indicating extreme risk to affected systems.

## Critical Vulnerabilities Discovered

**CVE-2025-20281** affects ISE and ISE-PIC versions 3.3 and later. This vulnerability allows attackers to execute arbitrary commands with root privileges by exploiting insufficient input validation. Attackers can send specially crafted API requests to gain elevated system access.

**CVE-2025-20282** impacts ISE and ISE-PIC version 3.4 specifically. This flaw enables attackers to upload malicious files to privileged system directories due to inadequate file validation checks. Once uploaded, these files can be executed with root privileges.

## Security Impact

Both vulnerabilities pose severe risks as they:
– Require no authentication to exploit
– Allow complete system compromise
– Grant attackers root-level access to affected devices
– Enable remote code execution on the underlying operating system

## Available Fixes

Cisco has released patches to address these vulnerabilities:

**For CVE-2025-20281:**
– ISE/ISE-PIC 3.3 Patch 6
– ISE/ISE-PIC 3.4 Patch 2

**For CVE-2025-20282:**
– ISE/ISE-PIC 3.4 Patch 2

## Immediate Action Required

Cisco confirms no workarounds exist for these vulnerabilities. Organizations using affected ISE products must immediately apply the available patches to prevent potential exploitation. While no active attacks have been reported, the critical nature of these flaws makes rapid patching essential.

The vulnerabilities were responsibly disclosed by security researchers Bobby Gould from Trend Micro Zero Day Initiative and Kentaro Kawane from GMO Cybersecurity.

Share This Article