CVE-2025-20337
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2025-20337 is an injection vulnerability in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The vulnerability was first disclosed on June 25, 2025, with CVE-2025-20337 added to the advisory on July 16, 2025, and active exploitation confirmed by July 21–25, 2025. Affected versions include Cisco ISE and ISE-PIC releases 3.3 (all patches through Patch 6) and 3.4 (base and Patch 1); releases 3.2 and earlier are not affected. It carries a CVSS v3.1 base score of 10.0 (Critical) (Cisco Advisory, CISA KEV).

Technical details

The root cause is insufficient validation of user-supplied input in a specific API endpoint of Cisco ISE and ISE-PIC, classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). An unauthenticated attacker can exploit this by submitting a specially crafted API request that bypasses input validation, ultimately achieving code execution with root privileges on the underlying operating system. No valid credentials are required, and the vulnerability is exploitable over the network with low attack complexity. The vulnerability was reported by Kentaro Kawane of GMO Cybersecurity by Ierae, working with Trend Micro Zero Day Initiative, and a public PoC was later published on GitHub (Cisco Advisory, ZDI Blog).

Impact

Successful exploitation grants an attacker full root-level control over the affected Cisco ISE or ISE-PIC appliance, resulting in complete compromise of confidentiality, integrity, and availability. Because Cisco ISE functions as a network access control and zero-trust policy enforcement platform, a compromised ISE instance can enable lateral movement across the enterprise network, unauthorized access to network segments, credential harvesting, and persistent backdoor installation. The CVSS scope is marked as Changed, reflecting the potential for impact beyond the vulnerable component itself (Cisco Advisory, CISA KEV).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Cisco ISE or ISE-PIC instances running versions 3.3 (any patch through Patch 6) or 3.4 (base or Patch 1) using network scanning tools such as Shodan, Censys, or Nmap targeting ISE management ports (typically TCP 443, 8443, or 9060).
  2. Identify target API endpoint: Locate the specific vulnerable API endpoint on the ISE appliance. Based on the advisory, the vulnerability resides in a specific API that accepts unauthenticated requests.
  3. Craft malicious API request: Construct a specially crafted HTTP/HTTPS API request containing injected special elements (per CWE-74) that bypass the insufficient input validation. No credentials are required.
  4. Submit the crafted request: Send the malicious API request to the target ISE appliance. The server-side processing of the injected input triggers code execution on the underlying OS.
  5. Achieve root code execution: The injected payload executes as the root user on the underlying operating system, granting full system control.
  6. Post-exploitation: Deploy a webshell or persistent backdoor, harvest credentials stored in ISE (including RADIUS secrets, AD integration credentials), and leverage ISE's network access control position to move laterally across the enterprise network (Cisco Advisory, AWS Blog, BleepingComputer).

Indicators of compromise

  • Network: Unexpected or anomalous unauthenticated API requests to Cisco ISE management interfaces (ports 443, 8443, 9060); outbound connections from ISE appliances to unknown external IPs; unusual HTTP POST requests to ISE API endpoints with malformed or oversized payloads.
  • File System: Presence of web shells or unexpected scripts in ISE application directories; new or modified files in privileged OS directories; unauthorized SSH keys added to root or admin accounts.
  • Logs: ISE application logs showing API requests from unexpected source IPs without authentication; OS-level logs (e.g., /var/log/messages, /var/log/secure) showing unusual process spawning from the ISE application process; Snort Rule 65075 triggers (provided by Cisco in the advisory).
  • Process: Unexpected child processes spawned by the ISE Java/application process (e.g., /bin/bash, curl, wget, python, nc); unusual cron jobs or scheduled tasks created under root context.
  • Persistence: New administrative accounts created in ISE; unauthorized changes to ISE policy configurations or network access rules (Cisco Advisory, AWS Blog).

Mitigation and workarounds

Cisco has released fixed software versions: ISE and ISE-PIC 3.3 Patch 7 (addresses CVE-2025-20337) and ISE and ISE-PIC 3.4 Patch 2 (addresses all three CVEs in the advisory). There are no workarounds available for this vulnerability. Organizations should immediately upgrade to the fixed releases; note that earlier hot patches (ise-apply-CSCwo99449_3.3.0.430_patch4 and ise-apply-CSCwo99449_3.4.0.608_patch1) did not address CVE-2025-20337 and have been deferred. As interim measures, restrict API access to ISE management interfaces via network segmentation and firewall rules, monitor for suspicious API activity, and consider temporary isolation of vulnerable systems until patching is complete. CISA's BOD 22-01 requires federal agencies to remediate by August 18, 2025 (Cisco Advisory, CISA KEV).

Community reactions

Cisco's PSIRT confirmed active exploitation attempts in July 2025 and updated the advisory multiple times, ultimately recommending ISE 3.3 Patch 7 and 3.4 Patch 2 as the definitive fixes. Amazon's security team published a detailed blog post attributing coordinated zero-day exploitation of CVE-2025-20337 and Citrix CVE-2025-5777 to an advanced APT group discovered through Amazon's MadPot honeypot service, generating significant media coverage across BleepingComputer, The Hacker News, The Record, CyberScoop, SecurityWeek, and Dark Reading (AWS Blog, BleepingComputer). The Zero Day Initiative published a technical write-up on the related CVE-2025-20281 API RCE class, and Forescout highlighted the irony of zero-trust enforcement infrastructure being exploited to bypass network perimeters (ZDI Blog). Community sentiment on Reddit and Mastodon reflected alarm at the pre-authentication, root-level severity of the flaw in a product specifically designed for identity and access control.

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management