Sploitus

CVE-2025-20281

13 known exploits for CVE-2025-20281

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

Affected products
Cisco Ise, Cisco Ise-Pic
Cisco Identity Services Engine
= 3.3.0, 3.4.0
Cisco Identity Services Engine Passive Identity Connector
= 3.3.0, 3.4.0
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
97.1% (100th percentile)
Weakness
CWE-74
NVD status
Analyzed
Published
2025-06-25
CVE-2025-20281 at NVD
Authoritative description, scoring and affected products

13 known exploits for CVE-2025-20281

Proof-of-concept code and exploit modules indexed by Sploitus