← Back

CVE-2025-20286

nvd nist
Published: Jun 4, 2025Modified: Oct 15, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed on cloud platforms, resulting in different Cisco ISE deployments sharing the same credentials. These credentials are shared across multiple Cisco ISE deployments as long as the software release and cloud platform are the same. An attacker could exploit this vulnerability by extracting the user credentials from Cisco ISE that is deployed in the cloud and then using them to access Cisco ISE that is deployed in other cloud environments through unsecured ports. A successful exploit could allow the attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. Note: If the Primary Administration node is deployed in the cloud, then Cisco ISE is affected by this vulnerability. If the Primary Administration node is on-premises, then it is not affected.

Affected (27)

1 product
Identity Services Engine
Configuration A
11 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.1.0
Version 3.1.0 patch10
Version 3.1.0 patch1
Version 3.1.0 patch2
Version 3.1.0 patch3
Version 3.1.0 patch4
Version 3.1.0 patch5
Version 3.1.0 patch6
Version 3.1.0 patch7
Version 3.1.0 patch8
Version 3.1.0 patch9
Running on/withPlatform Versions
Amazon
Amazon Web Services
All versions
Configuration B
1 platform
Running on/withPlatform Versions
Microsoft
Azure
All versions
Configuration C
16 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 3.2.0
Version 3.2.0 patch1
Version 3.2.0 patch2
Version 3.2.0 patch3
Version 3.2.0 patch4
Version 3.2.0 patch5
Version 3.2.0 patch6
Version 3.2.0 patch7
Version 3.3.0
Version 3.3.0 patch1
Version 3.3.0 patch2
Version 3.3.0 patch3
Version 3.3.0 patch4
Version 3.3.0 patch5
Version 3.4.0
Version 3.4.0 patch1
Running on/withPlatform Versions
Oracle
Cloud Infrastructure
All versions

Timeline

No history available yet.