VulnCity

Cisco ISE API Command Injection (1)

  • شناسه CVE: CVE-2025-20281
  • شدت: بحرانی
  • امتیاز CVSS: 9.8
  • فروشنده/سازنده: Cisco
Command InjectionCisco ISERCEAPI
A critical OS command injection vulnerability in the API of Cisco Identity Services Engine (ISE) allows unauthenticated remote code execution.

## Vulnerability Overview
Cisco ISE is a network access control and identity management solution widely deployed in enterprise environments. This vulnerability in the ISE API allows an unauthenticated attacker to inject arbitrary OS commands through specially crafted API requests, achieving code execution with root privileges.

## Technical Details
- **Type:** OS Command Injection (CWE-78)
- **Vulnerable Endpoint:** REST API for device profiling (/admin/API/mnt/Session/)
- **Root Cause:** User-supplied input in API parameters is passed directly to a shell command without proper sanitization. The vulnerable parameter is used in a system() call for device fingerprinting operations.
- **Authentication:** None required — the profiling API endpoint is accessible without credentials.

## Impact
- Complete compromise of the Cisco ISE appliance
- Access to all network access policies and configurations
- Ability to modify authentication and authorization rules
- RADIUS credential theft
- Network-wide access control bypass

## Affected Versions
- Cisco ISE 3.1 and earlier
- Cisco ISE 3.2 (before patch 5)
- Cisco ISE 3.3 (before patch 2)

نرم‌افزارهای تحت تأثیر

  • Cisco ISE (Identity Services Engine)