Cisco Releases Security Advisory Affecting Cisco Identity Service Engine
Advisory addresses a critical severity vulnerability in Cisco Identity Service Engine which could be exploited to allow a remote attacker to achieve high-level access
Summary
Advisory addresses a critical severity vulnerability in Cisco Identity Service Engine which could be exploited to allow a remote attacker to achieve high-level access
Affected platforms
The following platforms are known to be affected:
Threat details
Proof-of-Concept Exploit Code for CVE-2025-20286
The Cisco PSIRT is aware that proof-of-concept code is available for CVE-2025-20286.
Introduction
Cisco has released software updates for its Identity Service Engine (ISE). The updates address a critical severity vulnerability in the ISE product. Cisco Identity Services Engine (ISE) is a context-aware policy service to control access and threats across wired, wireless, and VPN networks.
- CVE-2025-20286 has a CVSSv3 score of 9.9 and is a "use of hard-coded password" vulnerability. An attacker could exploit this vulnerability to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.
Remediation advice
Affected organisations are encouraged to review Cisco Security Advisory cisco-sa-ise-aws-static-cred-FPMjUcm7 and apply the relevant updates.
Definitive source of threat updates
Last edited: 5 June 2025 2:55 pm