Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Cisco ISE and ISE-PIC Unauthenticated Remote Code Execution Vulnerability

Vulnerability

A vulnerability exists in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) versions 3.3 and later. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system with root privileges. The issue arises from insufficient validation of user-supplied input, enabling attackers to exploit the vulnerability by sending crafted API requests.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of code with root privileges on the affected system.

Remediation

Cisco has released patches for this vulnerability. Users can upgrade to Cisco ISE or ISE-PIC Release 3.3 Patch 6 or Release 3.4 Patch 2. Instructions for upgrading can be found on the Cisco Identity Services Engine support page.

Added: Jun 25, 2025, 4:25 PM
Updated: Jul 28, 2025, 2:52 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
9.4
remediation
7.7
relevance
0.2
threat
8.7
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.