Skip to main content

CVE detail

CVE-2025-20281

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS 10.0 · CriticalBuzz score 73.9KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 73.9

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 28.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
28.9
17 evidence mentions in the snapshot
Diversity score
20.0
9 sources across 6 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
17 source links · newest first
  • Amazon has seen a threat actor exploiting CVE-2025-20337 and CVE-2025-5777, two critical Cisco and Citrix vulnerabilities, as zero-days.

    newswww.securityweek.comNov 13, 2025, 9:50 AM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco ISE and PaperCut NG/MF flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the descriptions for these flaws: This week, Cisco confirmed attempted exploitation in […]

    newssecurityaffairs.comJul 28, 2025, 7:40 PM
  • 28th July – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 28th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The US Energy Department, including its National Nuclear Security Administration (NNSA), was reportedly breached as part of a Microsoft SharePoint vulnerability exploit. The breach was linked to a broader espionage campaign, that […]

    vendorresearch.checkpoint.comJul 28, 2025, 1:16 PM
  • CVE-2025-20281Horizon3.ai

    Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    exploithorizon3.aiJul 24, 2025, 6:21 PM
  • One or more vulnerabilities affecting Cisco Identity Services Engine (ISE) are being exploited in the wild, Cisco has confirmed by updating the security advisory for the flaws. About the vulnerabilities The three vulnerabilities affect Cisco’s Identity Services Engine (ISE) – a network security policy and access control system for enterprises – and Cisco ISE Passive Identity Connector (ISE-PIC), which is a lightweight identity service that allows Cisco ISE to passively gather user identity information. CVE-2025-20281 … More →

    newswww.helpnetsecurity.comJul 23, 2025, 11:37 AM
  • Cisco says it is aware of attempted exploitation of critical ISE vulnerabilities leading to unauthenticated remote code execution.

    newswww.securityweek.comJul 23, 2025, 9:01 AM
  • Cisco warns of active exploits targeting Identity Services Engine (ISE) and ISE-PIC flaws, first observed in July 2025. Cisco confirmed attempted exploitation in the wild of recently disclosed ISE and ISE-PIC flaws (CVE-2025-20281, CVE-2025-20282, CVE-2025-20337), updating its advisory after detecting attacks in July 2025. “Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE […]

    newssecurityaffairs.comJul 22, 2025, 7:52 PM
  • Cisco has dropped another maximum severity advisory detailing an unauthenticated remote code execution (RCE) flaw in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The networking equipment giant warned that the flaw, much similar to a critical bug it fixed last month, stems from insufficient input validation in a public API. “Cisco’s […]

    newswww.csoonline.comJul 18, 2025, 12:23 PM
  • Cisco warns of CVE-2025-20337, a critical ISE flaw (CVSS 10) allowing remote code execution with root privileges. Cisco addressed a critical vulnerability, tracked as CVE-2025-20337 (CVSS score of 10), in Identity Services Engine (ISE) and Cisco Identity Services Engine Passive Identity Connector (ISE-PIC). An attacker could trigger the vulnerability to execute arbitrary code on the […]

    newssecurityaffairs.comJul 17, 2025, 10:29 AM
  • Cisco has released patches for multiple vulnerabilities, including a critical flaw in Cisco ISE that leads to remote code execution (RCE).

    newswww.securityweek.comJul 17, 2025, 8:22 AM
  • 30th June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 29th June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Grocery giant Ahold Delhaize has disclosed a data breach that resulted in the theft of personal, financial, employment, and health information belonging to over 2.2 million individuals from its American business systems. […]

    vendorresearch.checkpoint.comJun 30, 2025, 11:25 AM
  • CSOs are being urged to quickly patch multiple vulnerabilities in Cisco Systems Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user. The fault behind both vulnerabilities: Holes in application programming interfaces (APIs). “Take this vulnerability seriously,” […]

    newswww.csoonline.comJun 27, 2025, 1:30 AM
  • Cisco released patches to address two critical vulnerabilities in ISE and ISE-PIC that could let remote attackers execute to code as root. Cisco addressed two critical vulnerabilities, tracked as CVE-2025-20281 and CVE-2025-20282, in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could allow remote, unauthenticated attackers to execute arbitrary code with root […]

    newssecurityaffairs.comJun 26, 2025, 12:25 PM
  • Two critical vulnerabilities in Cisco ISE could allow remote attackers to execute arbitrary code with root privileges.

    newswww.securityweek.comJun 26, 2025, 8:56 AM
  • No excerpt available.

    Exploitwww.zerodayinitiative.comJun 25, 2025, 4:15 PM
  • No excerpt available.

    Mitigationwww.cisa.govJun 25, 2025, 4:15 PM
  • No excerpt available.

    Vendor Advisorysec.cloudapps.cisco.comJun 25, 2025, 4:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence