Skip to main content

Cisco Releases Security Advisory Affecting Cisco Identity Service Engine

Advisory addresses a critical severity vulnerability in Cisco Identity Service Engine which could be exploited to allow a remote attacker to achieve high-level access

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Advisory addresses a critical severity vulnerability in Cisco Identity Service Engine which could be exploited to allow a remote attacker to achieve high-level access


Threat details

Proof-of-Concept Exploit Code for CVE-2025-20286

The Cisco PSIRT is aware that proof-of-concept code is available for CVE-2025-20286.


Introduction

Cisco has released software updates for its Identity Service Engine (ISE). The updates address a critical severity vulnerability in the ISE product. Cisco Identity Services Engine (ISE) is a context-aware policy service to control access and threats across wired, wireless, and VPN networks.

  • CVE-2025-20286 has a CVSSv3 score of 9.9 and is a "use of hard-coded password" vulnerability. An attacker could exploit this vulnerability to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.

Remediation advice

Affected organisations are encouraged to review Cisco Security Advisory cisco-sa-ise-aws-static-cred-FPMjUcm7 and apply the relevant updates.



Last edited: 5 June 2025 2:55 pm