
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20337 is an injection vulnerability in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The vulnerability was first disclosed on June 25, 2025, with CVE-2025-20337 added to the advisory on July 16, 2025, and active exploitation confirmed by July 21–25, 2025. Affected versions include Cisco ISE and ISE-PIC releases 3.3 (all patches through Patch 6) and 3.4 (base and Patch 1); releases 3.2 and earlier are not affected. It carries a CVSS v3.1 base score of 10.0 (Critical) (Cisco Advisory, CISA KEV).
The root cause is insufficient validation of user-supplied input in a specific API endpoint of Cisco ISE and ISE-PIC, classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). An unauthenticated attacker can exploit this by submitting a specially crafted API request that bypasses input validation, ultimately achieving code execution with root privileges on the underlying operating system. No valid credentials are required, and the vulnerability is exploitable over the network with low attack complexity. The vulnerability was reported by Kentaro Kawane of GMO Cybersecurity by Ierae, working with Trend Micro Zero Day Initiative, and a public PoC was later published on GitHub (Cisco Advisory, ZDI Blog).
Successful exploitation grants an attacker full root-level control over the affected Cisco ISE or ISE-PIC appliance, resulting in complete compromise of confidentiality, integrity, and availability. Because Cisco ISE functions as a network access control and zero-trust policy enforcement platform, a compromised ISE instance can enable lateral movement across the enterprise network, unauthorized access to network segments, credential harvesting, and persistent backdoor installation. The CVSS scope is marked as Changed, reflecting the potential for impact beyond the vulnerable component itself (Cisco Advisory, CISA KEV).
/var/log/messages, /var/log/secure) showing unusual process spawning from the ISE application process; Snort Rule 65075 triggers (provided by Cisco in the advisory)./bin/bash, curl, wget, python, nc); unusual cron jobs or scheduled tasks created under root context.Cisco has released fixed software versions: ISE and ISE-PIC 3.3 Patch 7 (addresses CVE-2025-20337) and ISE and ISE-PIC 3.4 Patch 2 (addresses all three CVEs in the advisory). There are no workarounds available for this vulnerability. Organizations should immediately upgrade to the fixed releases; note that earlier hot patches (ise-apply-CSCwo99449_3.3.0.430_patch4 and ise-apply-CSCwo99449_3.4.0.608_patch1) did not address CVE-2025-20337 and have been deferred. As interim measures, restrict API access to ISE management interfaces via network segmentation and firewall rules, monitor for suspicious API activity, and consider temporary isolation of vulnerable systems until patching is complete. CISA's BOD 22-01 requires federal agencies to remediate by August 18, 2025 (Cisco Advisory, CISA KEV).
Cisco's PSIRT confirmed active exploitation attempts in July 2025 and updated the advisory multiple times, ultimately recommending ISE 3.3 Patch 7 and 3.4 Patch 2 as the definitive fixes. Amazon's security team published a detailed blog post attributing coordinated zero-day exploitation of CVE-2025-20337 and Citrix CVE-2025-5777 to an advanced APT group discovered through Amazon's MadPot honeypot service, generating significant media coverage across BleepingComputer, The Hacker News, The Record, CyberScoop, SecurityWeek, and Dark Reading (AWS Blog, BleepingComputer). The Zero Day Initiative published a technical write-up on the related CVE-2025-20281 API RCE class, and Forescout highlighted the irony of zero-trust enforcement infrastructure being exploited to bypass network perimeters (ZDI Blog). Community sentiment on Reddit and Mastodon reflected alarm at the pre-authentication, root-level severity of the flaw in a product specifically designed for identity and access control.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."