By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Cisco Patches Critical ISE Vulnerabilities Enabling Root CmdExec and PrivEsc
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Cisco Patches Critical ISE Vulnerabilities Enabling Root CmdExec and PrivEsc
Tech News

Cisco Patches Critical ISE Vulnerabilities Enabling Root CmdExec and PrivEsc

By Viral Trending Content 2 Min Read
Share
SHARE

Feb 06, 2025Ravie LakshmananUnited States

Critical ISE Vulnerabilities

Cisco has released updates to address two critical security flaws Identity Services Engine (ISE) that could allow remote attackers to execute arbitrary commands and elevate privileges on susceptible devices.

The vulnerabilities are listed below –

  • CVE-2025-20124 (CVSS score: 9.9) – An insecure Java deserialization vulnerability in an API of Cisco ISE that could permit an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device.
  • CVE-2025-20125 (CVSS score: 9.1) – An authorization bypass vulnerability in an API of Cisco ISE could could permit an authenticated, remote attacker with valid read-only credentials to obtain sensitive information, change node configurations, and restart the node

An attacker could weaponize either of the flaws by sending a crafted serialized Java object or an HTTP request to an unspecified API endpoint, leading to privilege escalation and code execution.

Cybersecurity

Cisco said the two vulnerabilities are not dependent on one another and that there are no workarounds to mitigate them. They have been addressed in the below versions –

  • Cisco ISE software release 3.0 (Migrate to a fixed release)
  • Cisco ISE software release 3.1 (Fixed in 3.1P10)
  • Cisco ISE software release 3.2 (Fixed in 3.2P7)
  • Cisco ISE software release 3.3 (Fixed in 3.3P4)
  • Cisco ISE software release 3.4 (Not vulnerable)

Deloitte security researchers Dan Marin and Sebastian Radulea have been credited with discovering and repairing the vulnerabilities.

While the networking equipment major said it’s not aware of any malicious exploitation of the flaws, users are advised to keep their systems up-to-date for optimal protection.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Purple Promo Codes and Deals: Up to 30% Off

Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild

Optimism at 10-year high, as Europe’s technology sector hits $4trn mark

Honor 500 Release Date Announced as Specs Leak

What to Expect from Apple’s AirPods Pro 4 in 2026

TAGGED: API Security, Cisco, Cyber Security, Cybersecurity, Internet, network security, Patch Management, privilege escalation, Remote Code Execution, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article 30+ WB Movies Are Now Free On YouTube, Including One Of The Worst Films Ever Made
Next Article The AstraZeneca share price jumps 5% on today’s strong results – but is it too expensive?
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Next 1000x Crypto News Live Today: Early Alpha on the Latest Crypto Gems (November 19)
Crypto
See How Home Insurance Premiums Are Changing Near You
World News
Chinese astronauts left stranded after space debris smashes return craft
World News
Will the stock market crash before Christmas?
Business
Purple Promo Codes and Deals: Up to 30% Off
Tech News
Malaysia cracks down on crypto power theft as bitcoin mining drains the grid
Crypto
Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the Wild
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Next 1000x Crypto News Live Today: Early Alpha on the Latest Crypto Gems (November 19)

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Next 1000x Crypto News Live Today: Early Alpha on the Latest Crypto Gems (November 19)
November 19, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?