CVE-2025-20286 Details
Description
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected.
A vulnerability exists in Cisco Identity Services Engine (ISE) deployments on Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI). This vulnerability allows an unauthenticated, remote attacker to access sensitive data, perform limited administrative tasks, modify system configurations, or disrupt services. The issue arises because credentials are improperly generated during deployment, leading to different ISE instances sharing the same credentials. An attacker could exploit this by extracting credentials from one ISE deployment and using them to access another deployment in a different cloud environment through unsecured ports. This vulnerability affects Cisco ISE only when the Primary Administration node is deployed in the cloud.
Cisco has released software updates to address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For customers without service contracts, upgrades can be requested from the Cisco Technical Assistance Center (TAC).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco identity services engine | 3.1.0 - 3.1.0 patch1 3.1.0 patch10 3.1.0 patch2 3.1.0 patch3 3.1.0 patch4 3.1.0 patch5 3.1.0 patch6 3.1.0 patch7 3.1.0 patch8 3.1.0 patch9 3.2.0 - 3.2.0 patch1 3.2.0 patch2 3.2.0 patch3 3.2.0 patch4 3.2.0 patch5 3.2.0 patch6 3.2.0 patch7 3.3.0 3.3.0 patch1 3.3.0 patch2 3.3.0 patch3 3.3.0 patch4 3.3.0 patch5 3.4.0 3.4.0 patch1 |
CPE
Remediation
| |
| amazon amazon web services | All versions |
CPE
Remediation
| |
| microsoft azure | All versions |
CPE
Remediation
| |
| oracle cloud infrastructure | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 15, 2025 | Initial Analysis | [email protected] |
| Jun 5, 2025 | CVE Modified | [email protected] |
| Jun 4, 2025 | CVE Modified | [email protected] |
| Jun 4, 2025 | New CVE Received | [email protected] |