Cisco warns of max severity RCE flaws in Identity Services Engine

Cisco warns of max severity RCE flaws in Identity Services Engine

Cisco has issued warnings about two critical remote code execution vulnerabilities affecting its ISE platform, which could lead to full device takeover. Although no active exploits are reported, immediate patching is highly recommended to prevent potential attacks. #CiscoISE #RemoteCodeExecution

Keypoints

  • Cisco disclosed two max severity vulnerabilities (CVE-2025-20281 and CVE-2025-20282) in ISE and ISE-PIC.
  • The flaws allow unauthenticated remote attackers to execute arbitrary commands or upload malicious files with root privileges.
  • Cisco suggests updating to ISE versions 3.3 Patch 6 and 3.4 Patch 2 or later to mitigate the risks.
  • A separate medium-severity flaw (CVE-2025-20264) involves authorization bypass via SAML SSO integration.
  • No active exploitation cases are known, but timely patching is critical to defend against potential threats.

Read More: https://www.bleepingcomputer.com/news/security/cisco-warns-of-max-severity-rce-flaws-in-identity-services-engine/