Deserialization of untrusted data in Cisco Identity Services Engine (ISE) - CVE-2025-20124

 

Deserialization of untrusted data in Cisco Identity Services Engine (ISE) - CVE-2025-20124

Published: February 5, 2025 / Updated: June 20, 2025


Vulnerability identifier: #VU103657
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20124
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data. A remote user with read-only administrative credentials can send a specially crafted HTTP request to the affected API endpoint and execute arbitrary code on the target system with root privileges.



Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2025-20124

Install updates from vendor's website.

Cisco Identity Services Engine (ISE) - addressed in versions 3.1p10, 3.2P7, 3.3P4

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins