CVE-2025-20337 – Remote Code Execution (RCE) – Cisco Identity Services Engine (ISE)

ISGroup Cybersecurity

Cisco Identity Services Engine (ISE) is an access control and identity management platform that allows organizations to enforce security and compliance policies across their network infrastructure.
CVE‑2025‑20337 allows unauthenticated attackers to execute arbitrary commands with root privileges via specially crafted API requests.
The vulnerability stems from insufficient input validation in a vulnerable API endpoint.
The vulnerability affects Cisco ISE/ISE‑PIC versions prior to 3.3 Patch 7 and 3.4 Patch 2.

CVE‑2025‑20337 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

ProductCisco ISE
Date2025-07-19 13:24:46
Information
  • Fix Available

Technical Summary

This vulnerability stems from improper input handling in one of Cisco ISE’s web APIs. Specifically, the flaw lies in how user-supplied data is sanitized before execution within system commands.
An attacker can craft a malicious HTTP API request to achieve unauthenticated command injection, resulting in remote code execution with root-level access.

No authentication is required, and the attacker does not need elevated privileges, making this a critical issue.
Cisco ISE is often deployed in sensitive enterprise environments, which increases the risk of extensive lateral movement following exploitation.

Recommendations

  1. Update immediately: Update Cisco ISE/ISE‑PIC to version 3.3 Patch 7 or 3.4 Patch 2. Previous patches (e.g., CVE‑2025‑20281/20282) do not mitigate this vulnerability.

  2. Restrict API access: Ensure that the affected API endpoints are not publicly exposed. Limit management access to trusted internal networks.

  3. Verify and monitor: Monitor API request logs for unusual access patterns or suspicious parameters. Pay attention to execution anomalies and spikes in privileged access.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert