Логотип exploitDog
bind:CVE-2025-20337
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-20337

Количество 3

Количество 3

nvd логотип

CVE-2025-20337

7 месяцев назад

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-p9cx-6464-94g4

7 месяцев назад

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS3: 10
EPSS: Низкий
fstec логотип

BDU:2025-08631

8 месяцев назад

Уязвимость прикладного программного интерфейса платформы управления политиками соединений Cisco Identity Services Engine (ISE), связанная с непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код с root-привилегиями

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-20337

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS3: 10
1%
Низкий
7 месяцев назад
github логотип
GHSA-p9cx-6464-94g4

A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device.

CVSS3: 10
1%
Низкий
7 месяцев назад
fstec логотип
BDU:2025-08631

Уязвимость прикладного программного интерфейса платформы управления политиками соединений Cisco Identity Services Engine (ISE), связанная с непринятия мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код с root-привилегиями

CVSS3: 10
1%
Низкий
8 месяцев назад

Уязвимостей на страницу