VulnCity

Cisco ISE API Command Injection (2)

  • شناسه CVE: CVE-2025-20337
  • شدت: بحرانی
  • امتیاز CVSS: 9.1
  • فروشنده/سازنده: Cisco
Command InjectionCisco ISERCEAPI
A second OS command injection vulnerability in the Cisco ISE REST API, similar to CVE-2025-20281 but affecting a different API endpoint.

## Vulnerability Overview
This is a separate command injection flaw in the Cisco ISE administration API that allows unauthenticated attackers to execute arbitrary commands on the underlying operating system. While similar in nature to CVE-2025-20281, this vulnerability affects a different API endpoint and parameter.

## Technical Details
- **Type:** OS Command Injection (CWE-78)
- **Vulnerable Endpoint:** REST API endpoint for RADIUS accounting
- **Root Cause:** Similar to CVE-2025-20281 — unsanitized user input in API parameters passed to shell commands.
- **Key Difference:** Affects the accounting/log query functionality rather than session management.

## Impact
- Same as CVE-2025-20281: complete system compromise, credential theft, and network-wide access control bypass.
- Both vulnerabilities should be patched simultaneously.

نرم‌افزارهای تحت تأثیر

  • Cisco ISE (Identity Services Engine)