Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Cisco Warns of Critical ISE Flaw Allowing Unauthenticated Attackers to Execute Root Code

Posted on July 17, 2025July 17, 2025 By CWS

Jul 17, 2025Ravie LakshmananVulnerability / Community Safety
Cisco has disclosed a brand new maximum-severity safety vulnerability impacting Id Providers Engine (ISE) and Cisco ISE Passive Id Connector (ISE-PIC) that would allow an attacker to execute arbitrary code on the underlying working system with elevated privileges.
Tracked as CVE-2025-20337, the shortcoming carries a CVSS rating of 10.0 and is much like CVE-2025-20281, which was patched by the networking gear main late final month.
“A number of vulnerabilities in a particular API of Cisco ISE and Cisco ISE-PIC may enable an unauthenticated, distant attacker to execute arbitrary code on the underlying working system as root. The attacker doesn’t require any legitimate credentials to use these vulnerabilities,” the corporate stated in an up to date advisory.

“These vulnerabilities are as a result of inadequate validation of user-supplied enter. An attacker may exploit these vulnerabilities by submitting a crafted API request. A profitable exploit may enable the attacker to acquire root privileges on an affected machine.”
Kentaro Kawane of GMO Cybersecurity has been credited with discovering and reporting the flaw. Kawane was beforehand acknowledged for 2 different vital Cisco ISE flaws (CVE-2025-20286 and CVE-2025-20282) and one other vital bug in Fortinet FortiWeb (CVE-2025-25257)
CVE-2025-20337 impacts ISE and ISE-PIC releases 3.3 and three.4, no matter machine configuration. It doesn’t influence ISE and ISE-PIC launch 3.2 or earlier. The problem has been patched within the following variations –

Cisco ISE or ISE-PIC Launch 3.3 (Mounted in 3.3 Patch 7)
Cisco ISE or ISE-PIC Launch 3.4 (Mounted in 3.4 Patch 2)

There is no such thing as a proof that the vulnerability has been exploited in a malicious context. That stated, it is at all times a superb follow to make sure that programs are stored up-to-date to keep away from potential threats.
The disclosure comes as The Shadowserver Basis reported that menace actors are doubtless exploiting publicly launched exploits related to CVE-2025-25257 to drop internet shells on prone Fortinet FortiWeb cases since July 11, 2025.

As of July 15, there are estimated to be 77 contaminated cases, down from 85 the day earlier than. The vast majority of the compromises are concentrated round North America (44), Asia (14), and Europe (13).
Knowledge from the assault floor administration platform Censys exhibits that there are 20,098 Fortinet FortiWeb home equipment on-line, excluding honeypots, though it is at present not identified what number of of those are susceptible to CVE-2025-25257.
“This flaw allows unauthenticated attackers to execute arbitrary SQL instructions through crafted HTTP requests, resulting in distant code execution (RCE),” Censys stated.

Discovered this text fascinating? Observe us on Twitter  and LinkedIn to learn extra unique content material we submit.

The Hacker News Tags:Allowing, Attackers, Cisco, Code, Critical, Execute, Flaw, ISE, Root, Unauthenticated, Warns

Post navigation

Previous Post: Critical Cisco ISE Vulnerability Allows Remote Attacker to Execute Commands as Root User
Next Post: Cloudflare Confirms Recent 1.1.1.1 DNS Outage Caused by BGP Attack or Hijack

Related Posts

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices The Hacker News
251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and Elasticsearch The Hacker News
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain The Hacker News
Chinese Group Silver Fox Uses Fake Websites to Deliver Sainbox RAT and Hidden Rootkit The Hacker News
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor The Hacker News
Experts Detect Multi-Layer Redirect Tactic Used to Steal Microsoft 365 Login Credentials The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • How to Use Email Aliases for Privacy
  • 10 Best Cloud Penetration Testing Companies in 2025
  • 10 Best AI penetration Testing Companies in 2025
  • Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign
  • “GPUGate” Malware Abuses Uses Google Ads and GitHub to Deliver Advanced Malware Payload

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • How to Use Email Aliases for Privacy
  • 10 Best Cloud Penetration Testing Companies in 2025
  • 10 Best AI penetration Testing Companies in 2025
  • Noisy Bear Targets Kazakhstan Energy Sector With BarrelFire Phishing Campaign
  • “GPUGate” Malware Abuses Uses Google Ads and GitHub to Deliver Advanced Malware Payload

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News