LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-20337: Cisco Identity Services Engine Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 28, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 18, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-20337 to its Known Exploited Vulnerabilities catalog on Jul 28, 2025, with a federal patch deadline of Aug 18, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to…

CVE-2025-20337 is an injection vulnerability affecting Cisco Identity Services Engine (ISE) and Cisco ISE-PIC. It stems from insufficient validation of user-supplied input in a specific API, which can let an attacker submit a crafted API request and achieve remote code execution with root privileges on the device. Because ISE often sits at the center of network access control and identity enforcement, successful exploitation can give an attacker deep control over authentication decisions and connected infrastructure. Confirm all product and version details against the vendor advisory.

How it works

The flaw is classified as CWE-74, improper neutralization of special elements in output used by a downstream component (injection). In this case the vulnerable component is a specific API exposed by Cisco ISE and ISE-PIC. When the API receives input that is not properly validated or sanitized, an attacker can craft a request that injects malicious content. That content is then processed in a way that allows the attacker to execute arbitrary code and escalate to root privileges on the affected appliance. Public detail on the exact injection vector or required authentication level is limited; treat any unauthenticated or low-privilege access to the API as potentially dangerous until the vendor advisory clarifies the attack surface.

Am I affected? How to find it in your systems

Cisco ISE is commonly deployed as a virtual or physical appliance that provides network access control, 802.1X, guest services, and posture assessment. ISE-PIC is the Passive Identity Connector variant. Inventory every instance of these products in your environment—on-premises, virtual, or cloud-hosted—and note their software versions and whether the affected API is reachable from untrusted networks. Check management interfaces, API endpoints, and any load-balanced or reverse-proxied front ends that might expose the service. Review configuration backups, CMDB entries, and network diagrams for ISE nodes. Because exact vulnerable versions are not listed here, compare every discovered build against the official Cisco advisory. For detection of exploitation attempts, examine API access logs, authentication logs, and process-creation telemetry on the ISE host for anomalous requests or unexpected child processes running as root; escalate any such findings for forensic review.

How to remediate

Apply the vendor-supplied update or patch that addresses CVE-2025-20337 as soon as it is available and tested in your environment. Follow the remediation steps published in the Cisco security advisory exactly; do not rely on generic version ranges. After patching, verify that the vulnerable API behavior is no longer present and that the system is running the fixed software. In parallel, harden the remaining attack surface: restrict API access to management networks only, enforce strong authentication and least-privilege accounts, and disable any unused API endpoints or services. Align with CISA’s required action: apply mitigations per vendor instructions, follow BOD 22-01 guidance where cloud services are involved, or discontinue use of the product if no mitigations exist.

If you can't patch immediately

Until the official fix can be installed, reduce exposure with compensating controls. Segment ISE management and API interfaces onto isolated networks that are unreachable from general user or guest segments. Place a web application firewall or reverse proxy in front of the API and apply virtual-patching rules that block malformed or unexpected request patterns typical of injection attacks; tune these rules carefully to avoid breaking legitimate traffic. Disable the affected API feature entirely if operational requirements allow. Increase monitoring: forward ISE logs to a SIEM, alert on anomalous API calls or privilege escalations, and retain packet captures of management traffic for later analysis. These steps lower risk but do not eliminate it—schedule the permanent patch as the highest priority.

If your data may have been exposed

Actively exploited injection flaws that yield root access can lead to full compromise of the ISE appliance and any credentials, session data, or network policies it holds. Treat any confirmed exploitation as a potential breach: isolate the system, preserve forensic evidence, rotate secrets that may have been accessible, and follow your incident-response plan. Known ransomware use of this CVE is not documented, but the impact of root-level code execution remains severe. As a quick check for personal or organizational exposure in other incidents, you can run a free exposure scan of your email addresses against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · Identity Services Engine
WeaknessCWE-74
Added to CISA KEVJul 28, 2025
Federal patch deadlineAug 18, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities