Cisco ISE API Command Injection (2)
- شناسه CVE: CVE-2025-20337
- شدت: بحرانی
- امتیاز CVSS: 9.1
- فروشنده/سازنده: Cisco
Command InjectionCisco ISERCEAPI
A second OS command injection vulnerability in the Cisco ISE REST API, similar to CVE-2025-20281 but affecting a different API endpoint.
## Vulnerability Overview
This is a separate command injection flaw in the Cisco ISE administration API that allows unauthenticated attackers to execute arbitrary commands on the underlying operating system. While similar in nature to CVE-2025-20281, this vulnerability affects a different API endpoint and parameter.
## Technical Details
- **Type:** OS Command Injection (CWE-78)
- **Vulnerable Endpoint:** REST API endpoint for RADIUS accounting
- **Root Cause:** Similar to CVE-2025-20281 — unsanitized user input in API parameters passed to shell commands.
- **Key Difference:** Affects the accounting/log query functionality rather than session management.
## Impact
- Same as CVE-2025-20281: complete system compromise, credential theft, and network-wide access control bypass.
- Both vulnerabilities should be patched simultaneously.
## Vulnerability Overview
This is a separate command injection flaw in the Cisco ISE administration API that allows unauthenticated attackers to execute arbitrary commands on the underlying operating system. While similar in nature to CVE-2025-20281, this vulnerability affects a different API endpoint and parameter.
## Technical Details
- **Type:** OS Command Injection (CWE-78)
- **Vulnerable Endpoint:** REST API endpoint for RADIUS accounting
- **Root Cause:** Similar to CVE-2025-20281 — unsanitized user input in API parameters passed to shell commands.
- **Key Difference:** Affects the accounting/log query functionality rather than session management.
## Impact
- Same as CVE-2025-20281: complete system compromise, credential theft, and network-wide access control bypass.
- Both vulnerabilities should be patched simultaneously.
نرمافزارهای تحت تأثیر
- Cisco ISE (Identity Services Engine)