Target Industry

Indiscriminate, opportunistic targeting.

Overview

A critical vulnerability affecting Cisco Identity Services Engine (ISE) cloud deployments has been disclosed under CVE-2025-20286, with a CVSS score of 9.9. This flaw stems from the use of static credentials during deployment, resulting in multiple instances on the same cloud platform and software release sharing identical credentials. This significantly heightens the risk of unauthorised access across cloud environments including AWS, Azure, and Oracle Cloud Infrastructure (OCI). 

The vulnerability only impacts ISE when the Primary Administration node is deployed in the cloud. On-premises deployments are not affected. Cisco has confirmed the existence of proof-of-concept (PoC) exploit code, although no active exploitation has been observed to date. 

Impact

If successfully exploited, CVE-2025-20286 enables an unauthenticated attacker to extract credentials from one ISE cloud deployment and use them to access others on the same release and platform. This could allow threat actors to: 

  • View and extract sensitive data 
  • Conduct limited administrative actions 
  • Modify system configurations 
  • Disrupt ISE services within the affected deployment. 

Due to its cloud-centric nature, this vulnerability poses heightened risks to organisations operating multi-cloud infrastructures, particularly in hybrid environments where administrative functions may span both on-prem and cloud nodes. 

Affected Products

The following versions are affected: 

  • AWS: Cisco ISE 3.1, 3.2, 3.3, 3.4 
  • Azure: Cisco ISE 3.2, 3.3, 3.4 
  • OCI: Cisco ISE 3.2, 3.3, 3.4. 

No workaround fully mitigates the issue, though Cisco has offered limited recommendations for reducing risk. Full patching is advised. 

Exploitation

A PoC exploit is publicly available. However, there is currently no evidence of active exploitation in the wild. 

Containment, Mitigations & Remediations

Cisco has released patches to address CVE-2025-20286 and recommends immediate application. Other mitigations include: 

  • Restrict administrative access to trusted IP addresses via cloud security groups. 
  • Use the application reset-config ise command on affected instances. This resets credentials but also reverts the system to factory defaults – backups should be used cautiously as they may reintroduce the vulnerable state. 

Cisco’s advisory and update information can be found on their official security portal. 

Threat Landscape

Cisco ISE is widely adopted in enterprise environments for network access control and identity management. Its use in cloud infrastructure makes it a valuable target, especially in sectors with significant cloud dependency. The emergence of PoC code and shared credential weakness could encourage exploitation by threat actors scanning for exposed cloud-based ISE instances. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content