ID:11676 - Exploit for Deserialization of untrusted data in Cisco Identity Services Engine (ISE) - CVE-2025-20124

 
Main Vulnerability Database Exploits ID:11676 - Exploit for Deserialization of untrusted data in Cisco Identity Services Engine (ISE) - CVE-2025-20124

ID:11676 - Exploit for Deserialization of untrusted data in Cisco Identity Services Engine (ISE) - CVE-2025-20124

Published: June 20, 2025


Vulnerability identifier: #VU103657
Vulnerability risk: Medium
CVE-ID: CVE-2025-20124
CWE-ID: CWE-502
Exploitation vector: Remote access
Vulnerable software:
Cisco Identity Services Engine (ISE)

Link to public exploit:


Vulnerability description

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data. A remote user with read-only administrative credentials can send a specially crafted HTTP request to the affected API endpoint and execute arbitrary code on the target system with root privileges.



Remediation

Install updates from vendor's website.