
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20282 is a critical unauthenticated remote code execution vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows a remote attacker to upload arbitrary files and execute them as root on the underlying operating system. It was first published on June 25, 2025, and affects only Cisco ISE and ISE-PIC Release 3.4 (including 3.4.0 and 3.4.0-patch1); Release 3.3 and earlier are not affected by this specific CVE. The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical) (Cisco Advisory). It was reported by Kentaro Kawane of GMO Cybersecurity by Ierae, working with Trend Micro Zero Day Initiative (Cisco Advisory).
The root cause is classified as CWE-269 (Improper Privilege Management) — specifically, a lack of file validation checks in an internal API that fails to prevent uploaded files from being placed in privileged directories on the system (Cisco Advisory). An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the vulnerable internal API endpoint, uploading a malicious file that is then written to a privileged directory and subsequently executed as root. No valid credentials or prior access are required, and the vulnerability is exploitable over the network with low attack complexity and no user interaction. A public proof-of-concept is available on GitHub (PoC GitHub), and a detailed technical write-up has been published by OPSWAT focusing on the file validation failure (OPSWAT Blog).
Successful exploitation grants the attacker full root-level control over the affected Cisco ISE or ISE-PIC appliance, resulting in complete compromise of confidentiality, integrity, and availability (Cisco Advisory). Since Cisco ISE is a network access control and identity management platform, a compromised ISE node can expose authentication credentials, policy configurations, and network access control rules, enabling lateral movement across the enterprise network. Attackers could also use root access to pivot to other internal systems, exfiltrate sensitive identity data, or disrupt network access services for the entire organization (Arctic Wolf, Qualys ThreatProtect).
A public proof-of-concept exploit is available on GitHub (PoC GitHub). In July 2025, Cisco confirmed active exploitation attempts in the wild targeting CVE-2025-20281 and CVE-2025-20337 (related vulnerabilities in the same advisory); exploitation of CVE-2025-20282 has also been reported (Cisco Advisory, BleepingComputer). CISA added the Cisco ISE vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog in late July 2025 (Security Affairs). The EPSS score is approximately 0.00135, though the real-world exploitation risk is significantly elevated given the CVSS 10.0 rating, unauthenticated attack vector, and confirmed in-the-wild activity. No specific threat actor attribution has been publicly confirmed for CVE-2025-20282 at this time.
/var/log/messages or equivalent) showing unexpected process execution as root; authentication or authorization log anomalies indicating unauthorized access.bash, sh, curl, wget, python) running as root; unexpected cron jobs or scheduled tasks created on the ISE appliance.Cisco has released fixed software and confirms there are no workarounds available for CVE-2025-20282 (Cisco Advisory). The recommended remediation is to upgrade to Cisco ISE or ISE-PIC Release 3.4 Patch 2, which addresses all three CVEs in the advisory (CVE-2025-20281, CVE-2025-20282, and CVE-2025-20337). Release 3.3 Patch 7 addresses CVE-2025-20281 and CVE-2025-20337 but is not affected by CVE-2025-20282. Note that previously issued hot patches (ise-apply-CSCwo99449_3.3.0.430_patch4-SPA.tar.gz and ise-apply-CSCwo99449_3.4.0.608_patch1-SPA.tar.gz) did not address CVE-2025-20337 and have been deferred; organizations using these hot patches must upgrade to the full patch releases. As interim risk reduction, implement network segmentation to restrict access to ISE management interfaces to trusted administrative networks only, and monitor for suspicious file upload activity and unexpected process execution on ISE systems (Cisco Advisory, Qualys ThreatProtect).
Cisco's PSIRT issued and updated the advisory multiple times (versions 1.0 through 2.2) between June 25 and July 25, 2025, progressively adding new CVEs and confirming active exploitation (Cisco Advisory). Security media including BleepingComputer, The Hacker News, SecurityWeek, The Register, and SC World covered the vulnerabilities extensively, highlighting the rare CVSS 10.0 score and the unauthenticated attack vector (BleepingComputer, The Hacker News, The Register). Arctic Wolf, Qualys, SOCRadar, and CIS published threat intelligence advisories urging immediate patching (Arctic Wolf, CIS Advisory). Community discussion on Reddit's r/Cisco and r/cybersecurity reflected significant concern, with practitioners debating patch urgency and network segmentation strategies. CERT-EU and Singapore's CSA also issued independent advisories, reflecting broad international concern (CERT-EU, CSA Singapore).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."