CISCO ISE Under Fire: CVE-2025-20281 & 2025-20282 Deep Dive

Overview

Cisco has disclosed two critical, unauthenticated remote-code-execution (RCE) vulnerabilities in its Identity Services Engine (ISE), each rated 10.0 on the CVSS scale. Both flaws allow full root compromise of affected systems, and patches are now available.

ISE is Cisco’s flagship network access control platform, used by enterprises to enforce who and what can connect to corporate networks.1

 

CVE-2025-20281: Unauthenticated API RCE

  • Affected: ISE & ISE-PIC 3.3+
  • Issue: Insufficient validation of API input lets an unauthenticated attacker submit a crafted request that executes arbitrary OS commands as root.
  • Discovery: Trend Micro ZDI and GMO Cybersecurity (Ierae).
  • Read more: CVE-2025-20281 Report
  • Ask and explore: Consult the Q&A section and our A.I. Assistant on BaseFortify.eu for community insights and automated guidance.

 

CVE-2025-20282: Arbitrary File Upload & RCE

  • Affected: ISE & ISE-PIC 3.4 only
  • Issue: Lack of file-validation checks permits an unauthenticated attacker to upload malicious binaries into privileged directories, then execute them as root.
  • Read more: CVE-2025-20282 Report
  • Ask and explore: Consult the Q&A section and our A.I. Assistant on BaseFortify.eu for step-by-step exploit breakdowns.

 

Impact and Risk

Successful exploitation of either flaw yields complete root control over ISE servers. Attackers could exfiltrate sensitive certificates, pivot laterally, or disable network-based defenses. With no workarounds available, unpatched deployments remain at severe risk.

 

Mitigation and Updates

Cisco has released the following free patches:


– 3.3 Patch 6 for CVE-2025-20281
– 3.4 Patch 2 for CVE-2025-20282

 

To verify your version, log into the ISE CLI and run:

 

        ise/admin# show version

Confirm against Cisco’s fixed-release table to ensure you are no longer vulnerable.

 

How BaseFortify.eu Can Help

On BaseFortify.eu, you’ll find:


• Detailed CVE reports (including CVE-2025-20281 & CVE-2025-20282) with full technical write-ups
• Interactive Q&A where practitioners share exploit mitigations and best practices
• A.I. Assistant for on-demand, contextual answers to your security questions
• Real-time alerts, expert analysis, patch guidance, and customizable dashboards

 

Register now to unlock personalized vulnerability feeds, role-based reporting, and priority support: https://basefortify.eu/register

 

References

  1. Cisco PSIRT Advisory: Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities
  2. Cyber Security Agency of Singapore: Critical Vulnerabilities in Cisco ISE and ISE-PIC
  3. NVD Detail: CVE-2025-20282
  4. CISecurity.org Advisory: Multiple Vulnerabilities in Cisco ISE and ISE-PIC Could Allow Remote Code Execution
  5. Tenable CVE Entry: CVE-2025-20281
  6. Cisco 2016 Advisory: Using show version on ISE CLI
  7. BaseFortify.eu: CVE-2025-20281 Report
  8. BaseFortify.eu: CVE-2025-20282 Report