CVE-2025-20337 — Cisco Identity Services Engine Injection Vulnerability

CVE-2025-20337

Cisco ISE — Second Pre-Auth API Injection Enabling Root RCE (CVSS 10; Same Advisory as CVE-2025-20281)

What is Cisco Identity Services Engine?

Cisco Identity Services Engine (ISE) is the core network access control (NAC) and policy management platform used by enterprises to enforce who, what, and how devices connect to corporate networks. ISE authenticates users and devices, enforces security policies, and integrates with Active Directory, LDAP, and PKI infrastructure. Compromising ISE gives an attacker the ability to bypass network access controls, extract credential stores, and gain unrestricted network access across the enterprise. See also CVE-2025-20281, the companion injection vulnerability in the same advisory.

Overview

CVE-2025-20337 is the second of two CVSS 10.0 injection vulnerabilities (CWE-74) in Cisco ISE disclosed in advisory cisco-sa-ise-unauth-rce-ZAd2GnJ6, alongside CVE-2025-20281 and CVE-2025-20282. Like CVE-2025-20281, it allows an unauthenticated remote attacker to send a crafted API request injecting OS commands for root remote code execution — but via a distinct API endpoint. Both injection CVEs affect only ISE 3.3 and 3.4; earlier versions are not vulnerable. CISA added both to the KEV catalog simultaneously on July 28, 2025, confirming attempted exploitation.

Affected Versions

Product Vulnerable Fixed
Cisco ISE 3.3 All builds before Patch 7 ISE 3.3 Patch 7
Cisco ISE 3.4 All builds before Patch 2 ISE 3.4 Patch 2
Cisco ISE-PIC 3.3 All builds before Patch 7 ISE-PIC 3.3 Patch 7
Cisco ISE-PIC 3.4 All builds before Patch 2 ISE-PIC 3.4 Patch 2
Cisco ISE 3.2 and earlier Not affected

Technical Details

The vulnerability (CWE-74: Injection) is in a specific ISE REST API endpoint, distinct from the endpoint affected by CVE-2025-20281. Insufficient validation of user-supplied API request parameters allows injection of OS commands, achieving root-level code execution without authentication. Cisco deliberately withholds the specific endpoint name from the public advisory. The identical CVSS 10.0 score and impact as CVE-2025-20281 reflects that both flaws are equally severe and directly exploitable without authentication or any user interaction.

Discovery

Discovered by Kentaro Kawane of GMO Cybersecurity by Ierae (Japan), who also discovered the companion CVE-2025-20282 (file upload vulnerability).

Exploitation Context

Cisco PSIRT confirmed attempted exploitation of CVE-2025-20337 (and companion CVE-2025-20281) in the wild in July 2025. CISA added both to the KEV catalog on 28 July 2025 with a 21-day federal deadline. The simultaneous disclosure of two distinct unauthenticated RCE paths (CVE-2025-20281 and CVE-2025-20337) in the same ISE release indicates a systematic lack of input validation across the ISE API surface in versions 3.3 and 3.4.

Remediation

  1. Apply ISE 3.3 Patch 7 or ISE 3.4 Patch 2 immediately — patches address CVE-2025-20281, CVE-2025-20282, and CVE-2025-20337 together.
  2. Restrict ISE API network access to trusted administrative subnets — block external access to ISE admin and REST API interfaces at the perimeter firewall.
  3. Also see CVE-2025-20281 — both injection CVEs must be patched; neither is more critical than the other.
  4. Review ISE audit logs for unexpected API calls and validate all ISE policies for unauthorized changes.

Key Details

PropertyValue
CVE ID CVE-2025-20337
Vendor / Product Cisco — Identity Services Engine
NVD Published2025-07-16
NVD Last Modified2025-10-28
CVSS 3.1 Score10
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SeverityCRITICAL
CWE CWE-74 find similar ↗
CISA KEV Added2025-07-28
CISA KEV Deadline2025-08-18
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2025-08-18. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Timeline

DateEvent
2025-06-25Cisco advisory cisco-sa-ise-unauth-rce-ZAd2GnJ6 released (covers CVE-2025-20281, -20282, and -20337)
2025-07-16CVE-2025-20337 formally published
2025-07-28CISA adds CVE-2025-20281 and CVE-2025-20337 to KEV catalog
2025-08-18CISA BOD 22-01 remediation deadline