CVE-2025-20125
Description
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node.
This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
253.0.0+ 22 more
- (no CPE)range: 3.0.0
- cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*range: <3.1
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch9:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*
- Range: 3.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.