Skip to main content

Watch out, another max-severity, make-me-root Cisco bug on the loose

  • July 17, 2025
  • 0 replies
  • 3 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Three perfect 10s in the last month - ISE, ISE, baby

 

July 17, 2025 By Jessica Lyons

 

Cisco has issued a patch for a critical 10 out of 10 severity bug in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could allow an unauthenticated, remote attacker to run arbitrary code on the operating system with root-level privileges. 

ISE is a network access control and security policy management platform, and ISE-PIC centralizes identity management across security tools. And this vulnerability, tracked as CVE-2025-20337, is about the worst of the worst, allowing miscreants to take total control of compromised computers easily. In other words - patch now.

The vendor disclosed CVE-2025-20337 on Wednesday in an update to a June security advisory about two other max-severity flaws in the same products. The new bug is related to CVE-2025-20281, one of the two disclosed in June, which also received a 10 CVSS rating and affects ISE and ISE-PIC releases 3.3 and 3.4, regardless of device configuration. 

 

>>Full Article<<