cve-2025-20282

CRITICAL CVSS 10.0 opencve
Description

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.

Timeline
Published
2025-06-25 17:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H mitre
3.1 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H nvd
3.1 10.0 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "advisories": [
    {
      "id": "EUVD-2025-19166",
      "source": "euvd",
      "title": "A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.\r\n\r\nThis vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.",
      "url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19166"
    }
  ],
  "cve": "CVE-2025-20282",
  "epss": {
    "score": 0.29303
  },
  "mitre": {
    "cpes": [],
    "created": "2025-06-25T16:29:12.357000+00:00",
    "description": "A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.\r\n\r\nThis vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 10,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2025/20xxx/CVE-2025-20282.json",
    "references": [
      "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6"
    ],
    "title": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability",
    "updated": "2026-02-26T17:50:23.927000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-269"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
      "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
      "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
      "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*"
    ],
    "created": "2025-06-25T17:15:37.490000+00:00",
    "description": "A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.\r\n\r\nThis vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 10.0,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2025/CVE-2025-20282.json",
    "references": [
      "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6"
    ],
    "title": null,
    "updated": "2026-06-17T08:41:20.673000+00:00",
    "vendors": [
      "cisco",
      "cisco$PRODUCT$identity_services_engine",
      "cisco$PRODUCT$identity_services_engine_passive_identity_connector"
    ],
    "weaknesses": [
      "CWE-269"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-06-25T16:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.\r\n\r\nThis vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-269"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 10,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "d6f95697-14a6-4db9-b14c-3cd17f5fb7d4"
      },
      {
        "created": "2025-06-25T21:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "a14fdab1-77dd-4400-8559-7fb45d483ad3"
      },
      {
        "created": "2025-06-26T21:00:00+00:00",
        "data": [
          {
            "details": [
              "cisco",
              "cisco$PRODUCT$identity_services_engine",
              "cisco$PRODUCT$identity_services_engine_passive_identity_connector"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
                "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
                "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "cisco",
                "cisco$PRODUCT$identity_services_engine",
                "cisco$PRODUCT$identity_services_engine_passive_identity_connector"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "10e68b1f-f113-4348-a7fc-30c3ac4a6f35"
      },
      {
        "created": "2025-07-16T13:45:00+00:00",
        "data": [
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "epss": {
                  "new": {
                    "score": 0.00136
                  },
                  "old": {
                    "score": 0.00135
                  }
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "9bdccdb8-def7-4739-936a-7dfa3d3fadc3"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*",
        "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*",
        "cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2025-06-25T16:29:12.357000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.\r\n\r\nThis vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 10,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.29303
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-02-26T17:50:23.927000+00:00",
      "provider": "mitre"
    },
    "vendors": {
      "data": [
        "cisco",
        "cisco$PRODUCT$identity_services_engine",
        "cisco$PRODUCT$identity_services_engine_passive_identity_connector"
      ],
      "providers": [
        "nvd"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-269"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2025-06-25T16:29:12.357000+00:00",
    "description": "A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root.\r\n\r\nThis vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "Cisco ISE API Unauthenticated Remote Code Execution Vulnerability",
    "updated": "2025-06-25T20:10:14.597000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2025/20xxx/CVE-2025-20282.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON