Latest Cisco Identity Services Engine (ISE) vulnerability #
A vulnerability has been disclosed in certain cloud-deployed versions of Cisco Identity Services Engine (ISE) in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI). The vulnerability exists due to improper credential generation in cloud platform deployments resulting in shared credentials across deployments based on release and cloud platform.
It is important to note that Cisco ISE is affected by this vulnerability when the Primary Administration node is deployed in the cloud. An on-premises Primary Administration node is not affected.
The following platforms and versions are affected
- AWS Cisco ISE 3.1, 3.2, 3.3 and 3.4
- Azure Cisco ISE 3.2, 3.3 and 3.4
- OCI Cisco ISE 3.2, 3.3 and 3.4
This vulnerability has been designated CVE-2025-20286 and has a CVSS score of 9.9 (critical).
What is the impact? #
Successful exploitation of this vulnerability by an attacker would allow credentials extracted from a Cisco ISE instance to be used on others from the same release on the same cloud platform. This could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations or disrupt services within the impacted systems.
Are any updates or workarounds available? #
Cisco has released updates in the form of a hot fix for releases 3.1 through 3.4. Update to the latest version of the affected software when updates are available.
How do I find Cisco ISE installations with runZero? #
From the Software Inventory, use the following query to locate potentially impacted installations:
vendor:="Cisco" AND product:="Identity Services Engine"