← Back to browse · API

CVE-2025-20125

Severity
CRITICAL
CVSS
9.1
EPSS
0.16743
Risk score
42.26
CISA KEV
No
PoC
No
Published
2025-02-05
Modified
2025-02-05
First seen
2026-08-07
Aliases
EUVD-2025-2153, GHSA-HRPP-92F9-H887
Products
Cisco:Cisco ISE Passive Identity Connector 3.0.0, Cisco:Cisco ISE Passive Identity Connector 3.1.0, Cisco:Cisco ISE Passive Identity Connector 3.2.0, Cisco:Cisco ISE Passive Identity Connector 3.3.0, Cisco:Cisco Identity Services Engine Software 2.7.0 p8, Cisco:Cisco Identity Services Engine Software 3.0.0, Cisco:Cisco Identity Services Engine Software 3.0.0 p1, Cisco:Cisco Identity Services Engine Software 3.0.0 p2, Cisco:Cisco Identity Services Engine Software 3.0.0 p3, Cisco:Cisco Identity Services Engine Software 3.0.0 p4, Cisco:Cisco Identity Services Engine Software 3.0.0 p5, Cisco:Cisco Identity Services Engine Software 3.0.0 p6, Cisco:Cisco Identity Services Engine Software 3.0.0 p7, Cisco:Cisco Identity Services Engine Software 3.0.0 p8, Cisco:Cisco Identity Services Engine Software 3.1.0, Cisco:Cisco Identity Services Engine Software 3.1.0 p1, Cisco:Cisco Identity Services Engine Software 3.1.0 p2, Cisco:Cisco Identity Services Engine Software 3.1.0 p3, Cisco:Cisco Identity Services Engine Software 3.1.0 p4, Cisco:Cisco Identity Services Engine Software 3.1.0 p5, Cisco:Cisco Identity Services Engine Software 3.1.0 p6, Cisco:Cisco Identity Services Engine Software 3.1.0 p7, Cisco:Cisco Identity Services Engine Software 3.1.0 p8, Cisco:Cisco Identity Services Engine Software 3.1.0 p9, Cisco:Cisco Identity Services Engine Software 3.2.0, Cisco:Cisco Identity Services Engine Software 3.2.0 p1, Cisco:Cisco Identity Services Engine Software 3.2.0 p2, Cisco:Cisco Identity Services Engine Software 3.2.0 p3, Cisco:Cisco Identity Services Engine Software 3.2.0 p4, Cisco:Cisco Identity Services Engine Software 3.2.0 p5, Cisco:Cisco Identity Services Engine Software 3.2.0 p6, Cisco:Cisco Identity Services Engine Software 3.3 Patch 1, Cisco:Cisco Identity Services Engine Software 3.3 Patch 2, Cisco:Cisco Identity Services Engine Software 3.3 Patch 3, Cisco:Cisco Identity Services Engine Software 3.3.0
Sources
euvd EUVD-2025-2153

Description

A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.

References