ID:11676 - Exploit for Deserialization of untrusted data in Cisco Identity Services Engine (ISE) - CVE-2025-20124
Published: June 20, 2025
Cisco Identity Services Engine (ISE)
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote user with read-only administrative credentials can send a specially crafted HTTP request to the affected API endpoint and execute arbitrary code on the target system with root privileges.