CVE-2025-20282(cisco / identity_services_engine)

LOWCVSS 10.0 · CRITICAL

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent uploaded files from being placed in privileged directories on an affected system. An attacker could exploit this vulnerability by uploading a crafted file to the affected device. A successful exploit could allow the attacker to store malicious files on the affected system and then execute arbitrary code or obtain root privileges on the system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • identity_services_engine
  • identity_services_engine_passive_identity_connector

Affected systems

Vendors
Products
identity_services_engineidentity_services_engine_passive_identity_connector

1 version affected across 2 products

Deep dive

Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-20282 - critical 🚨 Cisco ISE < 3.4P2 - Unauthenticated Arbitrary File Upload > Cisco ISE and Cisco ISE-PIC contain an unrestricted file upload vulnerability caused ... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-20282 @pdnuclei #NucleiTemplates #cve

    Post summary

    Cisco ISE & ISE-PIC versions prior to 3.4P2 are vulnerable to an unauthenticated arbitrary file upload, with a PoC referenced via Project Discovery, but no patch or evidence of active exploitation is mentioned.

    01052526
    1.3K followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    🚨 Cisco ISE CVE-2025-20282 is now hitting KEVIntel sensors. We first saw exploitation on Aug 1, 4 days before Nuclei coverage appeared. 11 attempts 8 attacker IPs 4 countries Not in CISA KEV Unauthenticated root RCE. https://t.co/6BSW3005Pu

    Post summary

    CVE-2025-20282 is being actively exploited across multiple countries, with 11 attempts recorded, confirming an unauthenticated root RCE, but no patches or PoC details are shared.

    11020404
    61 followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    Full telemetry and exploitation timeline: https://kevintel.com/CVE-2025-20282 First observed: Aug 1 Last observed: Aug 6 Confidence: Confirmed

    Post summary

    The document documents that CVE-2025-20282 was actively exploited in the wild between August 1 and August 6, as evidenced by the reported telemetry timeline.

    0000064
    59 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--
Appciscoidentity_services_engine_passive_identity_connector3.4.0--

Explore more