CVE-2025-20125 Details
Description
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node. This vulnerability is due to a lack of authorization in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted HTTP request to a specific API on the device. A successful exploit could allow the attacker to attacker to obtain information, modify system configuration, and reload the device. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
An authorization bypass vulnerability has been identified in an API of Cisco Identity Services Engine (ISE). This vulnerability allows an authenticated, remote attacker with valid read-only administrative credentials to access sensitive information, modify node configurations, and restart the node. The issue arises from inadequate authorization in a specific API and improper validation of user-supplied data. Exploitation involves sending a crafted HTTP request to the affected API. In single-node deployments, restarting the node can disrupt authentication for new devices during the reload period.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found in the Cisco Identity Services Engine support page. Customers with service contracts should obtain the update through their usual channels. Those without service contracts can contact the Cisco Technical Assistance Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco identity services engine | < 3.1 3.1.0 - 3.1.0 patch1 3.1.0 patch2 3.1.0 patch3 3.1.0 patch4 3.1.0 patch5 3.1.0 patch6 3.1.0 patch7 3.1.0 patch8 3.1.0 patch9 3.2.0 - 3.2.0 patch1 3.2.0 patch2 3.2.0 patch3 3.2.0 patch4 3.2.0 patch5 3.2.0 patch6 3.3.0 - 3.3.0 patch1 3.3.0 patch2 3.3.0 patch3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 28, 2025 | Initial Analysis | [email protected] |
| Feb 5, 2025 | New CVE Received | [email protected] |