Target Industry
Indiscriminate, opportunistic targeting.
Overview
A critical vulnerability affecting Cisco Identity Services Engine (ISE) cloud deployments has been disclosed under CVE-2025-20286, with a CVSS score of 9.9. This flaw stems from the use of static credentials during deployment, resulting in multiple instances on the same cloud platform and software release sharing identical credentials. This significantly heightens the risk of unauthorised access across cloud environments including AWS, Azure, and Oracle Cloud Infrastructure (OCI).
The vulnerability only impacts ISE when the Primary Administration node is deployed in the cloud. On-premises deployments are not affected. Cisco has confirmed the existence of proof-of-concept (PoC) exploit code, although no active exploitation has been observed to date.
Impact
If successfully exploited, CVE-2025-20286 enables an unauthenticated attacker to extract credentials from one ISE cloud deployment and use them to access others on the same release and platform. This could allow threat actors to:
- View and extract sensitive data
- Conduct limited administrative actions
- Modify system configurations
- Disrupt ISE services within the affected deployment.
Due to its cloud-centric nature, this vulnerability poses heightened risks to organisations operating multi-cloud infrastructures, particularly in hybrid environments where administrative functions may span both on-prem and cloud nodes.
Affected Products
The following versions are affected:
- AWS: Cisco ISE 3.1, 3.2, 3.3, 3.4
- Azure: Cisco ISE 3.2, 3.3, 3.4
- OCI: Cisco ISE 3.2, 3.3, 3.4.
No workaround fully mitigates the issue, though Cisco has offered limited recommendations for reducing risk. Full patching is advised.
Exploitation
A PoC exploit is publicly available. However, there is currently no evidence of active exploitation in the wild.
Containment, Mitigations & Remediations
Cisco has released patches to address CVE-2025-20286 and recommends immediate application. Other mitigations include:
- Restrict administrative access to trusted IP addresses via cloud security groups.
- Use the application reset-config ise command on affected instances. This resets credentials but also reverts the system to factory defaults – backups should be used cautiously as they may reintroduce the vulnerable state.
Cisco’s advisory and update information can be found on their official security portal.
Threat Landscape
Cisco ISE is widely adopted in enterprise environments for network access control and identity management. Its use in cloud infrastructure makes it a valuable target, especially in sectors with significant cloud dependency. The emergence of PoC code and shared credential weakness could encourage exploitation by threat actors scanning for exposed cloud-based ISE instances.
Further Information













