CVE-2025-20124
Severity CVSS v4.0:
Pending analysis
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
05/02/2025
Last modified:
28/03/2025
Description
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device.<br />
<br />
This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected API. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges.<br />
Note:&nbsp;To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:* | 3.1 (excluding) | |
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch9:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:* | ||
| cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



