Medium severity6.5NVD Advisory· Published Jul 16, 2025· Updated Jun 17, 2026
CVE-2025-20283
CVE-2025-20283
Description
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root.
This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute commands as the root user. To exploit this vulnerability, the attacker must have valid high-privileged credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*range: <3.3.0
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch6:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine:3.4.0:patch1:*:*:*:*:*:*
- (no CPE)range: 3.3.0
cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:*:*:*:*:*:*:*:*range: <3.3.0
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch1:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch2:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch3:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch4:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch5:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.3.0:patch6:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:-:*:*:*:*:*:*
- cpe:2.3:a:cisco:identity_services_engine_passive_identity_connector:3.4.0:patch1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.