Ciscoが重大な脆弱性3件を修正――影響を受ける製品一覧

Ciscoのアイデンティティサービスに、3件の別個の脆弱性が影響する。すべて修正済みだ。

Written By
Megan Crouse
Megan Crouse
Jul 25, 2025
1 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

この記事はTechRepublicで最初に公開された。

Ciscoは7月17日のアドバイザリーで、Cisco Identity Services Engine(ISE)とCisco ISE Passive Identity Connector(ISE-PIC)に存在する深刻な脆弱性により、認証されていないリモート攻撃者がroot権限でコマンドを実行できる可能性があると発表した。

Ciscoはこの問題に対する複数のパッチをリリースし、特定のソフトウェアバージョン向けには修正範囲を拡大したパッチも提供している。

この脆弱性は、Trend Micro Zero Day InitiativeのBobby Gould氏と、Trend Micro Zero Day Initiativeと協力していたGMO Cybersecurity by IeraeのKentaro Kawane氏によって報告された。

脆弱性により任意コード実行が可能に

Ciscoのパッチが対処する3件の脆弱性:CVE-2025-20281、CVE-2025-20337、CVE-2025-20282だ。いずれも任意コード実行の脆弱性だが、互いに関連はなく、効果を発揮させるために併せて悪用する必要もない。

CVE-2025-20281とCVE-2025-20337は、Cisco ISEおよびCisco ISE-PICに対するリモートコード実行を可能にする。攻撃者は、ユーザーが入力したデータの検証が不十分である点を突く、細工したAPIリクエストを送信できる。これにより、rootレベルの権限を取得される可能性がある。

CVE-2025-20282は、Cisco ISEおよびISE-PICのリリース3.4に影響する。この脆弱性を悪用すると、攻撃者は細工したファイルをデバイスにアップロードできる。ファイルの検証が行われないため、そのファイルを特権ディレクトリに配置でき、攻撃者が任意のコードを実行したり、rootアクセスを取得したりする可能性がある。

Ciscoは、これらの脆弱性が現在悪用されていることを把握していないと述べている。

脆弱性を修正する方法

Cisco ISEが次のバージョンで動作していれば、これらの脆弱性に対するパッチが適用されている。

  • リリース3.4パッチ2
  • リリース3.3パッチ6(リリース3.3パッチ7適用済み)

Ciscoはこれらに先立ってホットパッチもリリースしていたが、現在は上記のバージョンに置き換えられている。同社はアップデートの適用方法に関するガイドも提供している。

Ciscoに関するその他のニュース

関連するサイバーセキュリティニュースとして、約1カ月前にはCiscoのセキュリティインテリジェンス部門であるTalosが、生成AIを利用したマルウェア配布を餌にする脅威アクターのグループを発見した。攻撃者は実在する企業のウェブサイトを偽装したサイトを使い、被害者のコンピューター上の特定の文書をロックするランサムウェア「CyberLock」を配布していた。偽サイトでは、ChatGPTのダウンロード版を提供すると謳っていた。

また、サイバーセキュリティ教育を広く推進する取り組みとして、Ciscoは3月に欧州連合全域でデジタルスキル研修を行う取り組みを開始した。Cisco’s Networking Academyを通じて提供される無料講座では、ネットワーキングとサイバーセキュリティに不可欠なスキルをより多くの人に身につけてもらうことを目指している。

Megan Crouse

Megan Crouse has a decade of experience in business-to-business news and feature writing, including as first a writer and then the editor of Manufacturing.net. Her news and feature stories have appeared in Military & Aerospace Electronics, Fierce Wireless, TechRepublic, and eWeek. She copyedited cybersecurity news and features at Security Intelligence. She holds a degree in English Literature and minored in Creative Writing at Fairleigh Dickinson University.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.