Use of Hard-coded Password in Cisco Identity Services Engine (ISE) - CVE-2025-20286

 

Use of Hard-coded Password in Cisco Identity Services Engine (ISE) - CVE-2025-20286

Published: June 5, 2025


Vulnerability identifier: #VU110217
CSH Severity: High
CVSS v4: 7.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:H]
CVE-ID: CVE-2025-20286
CWE-ID: CWE-259
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper generation of credentials during the deployment of Cisco ISE on cloud platforms. A remote attacker can access sensitive data, execute limited administrative operations, modify system configurations or disrupt services within the impacted systems.


Affected software

Cisco Identity Services Engine (ISE)

How to mitigate CVE-2025-20286

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins