CVE-2025-20337
CRITICAL CISA KEVDescription
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
| cisco | identity_services_engine_passive_identity_connector |
References
Frequently Asked Questions
What is CVE-2025-20337? +
How severe is CVE-2025-20337? +
What products are affected by CVE-2025-20337? +
How do I check if I'm vulnerable to CVE-2025-20337? +
Related Vulnerabilities
Git LFS is a Git extension for versioning large files. When Git LFS requests credentials from Git for a remote …
Integrated Scripting is a tool for creating scripts for handling complex operations in Integrated Dynamics. Minecraft users who use Integrated …
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1; Parsoid: before 0.16.5, 0.19.2, 0.20.2.
Host Header Injection (HHI) vulnerability in the Hotspot Shield VPN client, which can induce unexpected behaviour when accessing third-party web …
Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed …
A security issue affecting multiple Cisco devices also directly impacts Stratix® 5410, 5700, and 8000 devices. This can lead to …