CVE-2025-20124
CVSS 3.1 Score 9.9 of 10 (high)
Details
Summary
CVE-2025-20124 is a vulnerability affecting the API of Cisco ISE. This issue allows authenticated, remote attackers to execute arbitrary commands as the root user on an affected device. The root cause is insecure deserialization of user-supplied Java byte streams in the software. An attacker can exploit this vulnerability by sending a specially crafted serialized Java object to the API. Successful exploitation enables the attacker to execute arbitrary commands on the device and elevate privileges. Note that to exploit this vulnerability, the attacker must possess valid read-only administrative credentials, and in a single-node deployment, new devices will be unable to authenticate during the reload time.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.