Cisco Patches Three Critical Vulnerabilities – Here are the Products Affected

Three separate vulnerabilities impact Cisco’s identity services. All have been patched.

執筆者
Megan Crouse
Megan Crouse
Published: Jul 25, 2025
Updated: Jul 26, 2025
2 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

This article was originally published on TechRepublic.

Severe vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated remote attacker to issue commands with root privileges, Cisco said in an advisory on July 17. 

Cisco released multiple patches for the issues, including an expanded fix for specific software versions.

The vulnerabilities were reported by Bobby Gould of Trend Micro Zero Day Initiative and Kentaro Kawane of GMO Cybersecurity by Ierae, working with Trend Micro Zero Day Initiative. 

The vulnerabilities allow for arbitrary code execution

Cisco’s patches address three vulnerabilities: CVE-2025-20281, CVE-2025-20337, and CVE-2025-20282. All are arbitrary code execution vulnerabilities, but they are not related to each other and do not need to be exploited together to be effective. 

CVE-2025-20281 and CVE-2025-20337 open up Cisco ISE and Cisco ISE-PIC to remote code execution. An attacker could submit a crafted API request that took advantage of the insufficient validation of user-supplied input. This could grant root-level privileges.

CVE-2025-20282 affects Cisco ISE and ISE-PIC Release 3.4. With it, an attacker could have uploaded a crafted file to the device. Due to a lack of file validation, the file could be placed in privileged directories, allowing the attacker to execute arbitrary code or gain root access. 

Cisco said it is not aware of any active exploitation of these vulnerabilities. 

How to patch the vulnerabilities  

Your Cisco ISE is patched against these vulnerabilities if it is running the following versions:

  • Release 3.4 Patch 2
  • Release 3.3 Patch 6 (with Release 3.3 Patch 7)

Cisco released hot patches prior to these, but they have been superseded by the versions listed above. The company has also provided guides on how to apply updates.

Other news from Cisco 

In related cybersecurity news, about a month ago Talos, Cisco’s security intelligence division, discovered a threat actor group using the promise of generative AI as a bait to distribute malware. The attackers used a spoofed version of a real business’ website to distribute the ransomware strain called CyberLock, which locked specific documents on the victims’ computer. The fake site promised a downloadable version of ChatGPT.  

Separately, in a broader push for cybersecurity education, Cisco in March launched a digital skills training initiative across the European Union. The free courses, offered through Cisco’s Networking Academy, aim to equip more individuals with essential skills in networking and cybersecurity.  

Megan Crouse

Megan Crouse has a decade of experience in business-to-business news and feature writing, including as first a writer and then the editor of Manufacturing.net. Her news and feature stories have appeared in Military & Aerospace Electronics, Fierce Wireless, TechRepublic, and eWeek. She copyedited cybersecurity news and features at Security Intelligence. She holds a degree in English Literature and minored in Creative Writing at Fairleigh Dickinson University.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。