CVE-2025-20281

CRITICAL(10.0)KEVLikely Exploited

Cisco Identity Services Engine Injection Vulnerability

Description

CVE-2025-20281 is a critical injection vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that allows an unauthenticated, remote attacker to execute arbitrary code as root on the underlying operating system. The flaw resides in a specific API endpoint where insufficient validation of user-supplied input enables an attacker to submit crafted API requests that bypass security controls entirely. With the maximum possible CVSS v3.1 base score of 10.0, this vulnerability poses a catastrophic risk to network access control infrastructure. CISA has added CVE-2025-20281 to the Known Exploited Vulnerabilities catalog with a remediation deadline of August 18, 2025, and its EPSS score of 30.42% at the 96th percentile signals a very high probability of exploitation in the wild.

KEV Information

Vendor
Cisco
Product
Identity Services Engine
Date Added
July 28, 2025
Due Date
August 18, 2025
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0

CWEs

Affected Products

VendorProductVersion
ciscoidentity services engine3.3.0; 3.4.0
ciscoidentity services engine passive identity connector3.3.0; 3.4.0

References

Weakness Type

CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)

CVE-2025-20281 is classified under CWE-74, which describes vulnerabilities where an application fails to properly neutralize special elements before passing data to a downstream component. In Cisco ISE, the affected API endpoint incorporates user-supplied input into operations that are interpreted by the underlying operating system without adequate sanitization. This allows an attacker to inject special elements that alter the intended behavior, leading to arbitrary code execution with root privileges.

Learn more: CWE-74 — Improper Neutralization of Special Elements in Output Used by a Downstream Component

Impact Analysis

CVE-2025-20281 represents one of the most severe vulnerabilities possible, achieving the maximum CVSS v3.1 score of 10.0 (Critical). The vulnerability is remotely exploitable over the network (AV:N) with low attack complexity (AC:L), requiring no authentication (PR:N) and no user interaction (UI:N). The scope is changed (S:C), meaning a successful exploit can affect resources beyond the vulnerable ISE component itself, potentially compromising the entire network access control infrastructure. All three dimensions of the CIA triad face maximum impact: Confidentiality (High) means attackers can access all data on the ISE appliance including user credentials, certificates, and network policies; Integrity (High) enables modification of authentication rules and network access policies; and Availability (High) allows complete disruption of network access services. With an EPSS score of 30.42%, this vulnerability ranks in the 96th percentile for exploitation probability, underscoring the urgency of immediate remediation.

Exploit Maturity

CVE-2025-20281 exhibits significant exploit maturity. CISA has confirmed active exploitation in the wild by adding this vulnerability to the Known Exploited Vulnerabilities catalog, and public exploit code is available via the Zero Day Initiative analysis. The EPSS score of 30.42% at the 96th percentile places it among the top 4% of all vulnerabilities by exploitation probability. While CISA classifies the ransomware association as unknown for this CVE, the combination of unauthenticated remote code execution with root privileges and public exploit availability makes this an extremely attractive target for threat actors of all sophistication levels.

Remediation

  1. Apply vendor patches immediately. Cisco has released security updates to address CVE-2025-20281. Organizations running Cisco ISE or ISE-PIC versions 3.3.0 or 3.4.0 must upgrade to the fixed releases as detailed in the Cisco Security Advisory. Follow CISA's BOD 22-01 guidance if mitigations are unavailable.

  2. Restrict API access. Implement network-level access controls to limit which hosts can reach the vulnerable ISE API endpoints. Use firewall rules or access control lists to ensure only trusted management networks can communicate with ISE administrative interfaces.

  3. Monitor for indicators of compromise. Review ISE application logs and system audit trails for unusual API requests, unexpected process executions, new user accounts, or changes to network access policies. Given that exploitation grants root access, check for persistence mechanisms such as modified system files, cron jobs, or unauthorized SSH keys.

  4. Segment ISE infrastructure. Ensure that ISE appliances are deployed in a dedicated management network segment with strict ingress and egress controls. This limits an attacker's ability to pivot from a compromised ISE instance to other network resources.

  5. Implement defense-in-depth input validation. Long-term, ensure that all API endpoints in your network infrastructure enforce strict input validation, parameterized queries, and least-privilege execution contexts to prevent injection-class vulnerabilities.

Technical Details

CVE-2025-20281 is an injection vulnerability in a specific API of Cisco ISE and ISE-PIC, with the CVSS v3.1 vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The vulnerability arises from insufficient validation of user-supplied input in API request processing. When the ISE application receives a crafted API request, it passes the user-controlled data to a downstream component — the underlying operating system — without properly neutralizing special elements that can alter the command or operation being executed. This lack of sanitization enables an attacker to inject arbitrary payloads that the operating system interprets and executes with root privileges, since the ISE service process runs with elevated permissions. The changed scope (S:C) in the CVSS vector reflects that compromise of the ISE API component directly enables control over the host operating system and, by extension, the network access control policies enforced across the enterprise. No credentials of any kind are required, and the attack can be launched remotely with a single crafted HTTP request to the vulnerable API endpoint.

Frequently Asked Questions

Is CVE-2025-20281 being actively exploited?

Yes. CISA has added CVE-2025-20281 to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Public exploit code is available through the Zero Day Initiative, and the EPSS score of 30.42% at the 96th percentile indicates a very high likelihood of continued exploitation.

What products are affected by CVE-2025-20281?

Cisco Identity Services Engine (ISE) versions 3.3.0 and 3.4.0, as well as Cisco ISE Passive Identity Connector (ISE-PIC) versions 3.3.0 and 3.4.0, are affected. Organizations should consult the Cisco Security Advisory for the specific fixed releases.

How do I fix CVE-2025-20281?

Apply the security updates provided by Cisco as detailed in their advisory (cisco-sa-ise-unauth-rce-ZAd2GnJ6). In the interim, restrict network access to ISE API endpoints and monitor for signs of compromise. CISA mandates remediation by August 18, 2025.

How severe is CVE-2025-20281?

CVE-2025-20281 carries the maximum CVSS v3.1 base score of 10.0 (Critical). It allows unauthenticated remote code execution as root, requires no user interaction, and has low attack complexity. The EPSS score places it in the 96th percentile for exploitation probability, making it one of the most dangerous actively exploited vulnerabilities.

CVSS Score

10.0
CRITICAL(10.0)

EPSS Score

EPSS Score97.07%
EPSS Percentile99.9%

Dates

PublishedJune 25, 2025
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.