Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2025/07/cisco-warns-of-critical-ise-flaw.html
ONE SENTENCE SUMMARY:
A critical Cisco security vulnerability could allow unauthorized remote code execution in ISE systems, urging immediate patching and system updates.
MAIN POINTS:
- New vulnerability affects Cisco ISE, allowing arbitrary code execution with root privileges.
- Tracked as CVE-2025-20337 with a maximum CVSS score of 10.0.
- Similar to CVE-2025-20281, recently patched.
- Exploitable through crafted API requests due to insufficient input validation.
- Kentaro Kawane credited with discovering the flaw.
- Affects ISE versions 3.3 and 3.4, fixed in specific patches.
- No current evidence of malicious exploitation of this vulnerability.
- Related exploits in Fortinet FortiWeb are reportedly being used maliciously.
- 77 FortiWeb instances compromised, primarily in North America, Asia, and Europe.
- Censys reports 20,098 online FortiWeb appliances, with unknown vulnerability status.
TAKEAWAYS:
- Patch ISE systems immediately to safeguard against CVE-2025-20337.
- Ensure robust validation procedures for API inputs to prevent exploits.
- Continually monitor security advisories for timely updates.
- Stay informed of related exploits affecting similar systems like FortiWeb.
- Regular system updates are crucial to minimize security threats.