> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2025-20281 & CVE-2025-20282: Unauthenticated RCE Vulnerabilities in Cisco ISE and ISE-PIC
- URL: https://darkwebinformer.com/cve-2025-20281-cve-2025-20282-unauthenticated-rce-vulnerabilities-in-cisco-ise-and-ise-pic/
- Published: 2025-06-30T19:28:04.000Z
- Updated: 2025-09-04T22:21:31.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

---

## 🧠 TL;DR

Two critical vulnerabilities (CVE-2025-20281 and CVE-2025-20282) have been discovered in Cisco Identity Services Engine (ISE) and ISE-PIC. These flaws allow **unauthenticated remote code execution** on affected systems. A working proof-of-concept (PoC) exploit is available publicly, and over 1,900 exposed systems have been identified via ZoomEye.

---

## 📋 Vulnerability Details

### CVE-2025-20281

- **Type:** Unauthenticated RCE
- **Component:** Cisco ISE
- **CVSS Score:** 10.0 (Critical)
- **Description:** Allows unauthenticated attackers to execute arbitrary code due to improper input validation.

### CVE-2025-20282

- **Type:** Unauthenticated RCE
- **Component:** Cisco ISE-PIC
- **CVSS Score:** 10.0 (Critical)
- **Description:** A related vulnerability enabling remote code execution through a similar attack surface as CVE-2025-20281.

---

## 🧪 Proof of Concept (PoC)

A working PoC has been released demonstrating the exploitation of both vulnerabilities:

🔗 [PoC on GitHub](https://github.com/abrewer251/CVE-2025-20281-2-Citrix-ISE-RCE)

---

## 🔍 Threat Hunting

### ZoomEye Dork

iniCopyEdit`app="Cisco ISE"`  

### Live Search

🔗 [ZoomEye Search Results](https://www.zoomeye.ai/searchResult?q=YXBwPSJDaXNjbyBJU0Ui)

**Exposed Systems:** 1,937 at the time of writing.

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/06/349067982735987432982739823-1.png)

Follow [@zoomeye\_team](https://x.com/zoomeye%5Fteam)'s official Twitter/X account and send the message “Dark Web Informer” via DM to receive an extra 15-day membership.

---

## 📄 Official Advisories

- [GHSA-rc4f-42xm-hvjw](https://github.com/advisories/GHSA-rc4f-42xm-hvjw)
- [GHSA-w8p2-wjjr-hr24](https://github.com/advisories/GHSA-w8p2-wjjr-hr24)

---

## 🛡️ Recommended Action

- Immediately restrict external access to Cisco ISE and ISE-PIC interfaces.
- Apply patches or mitigations from Cisco (if available).
- Monitor for unusual activity and potential exploitation attempts.
- Review firewall and access control policies for exposed management interfaces.

---

## 🎯 Affected Environments

- Cisco Identity Services Engine (ISE)
- Cisco ISE Passive Identity Connector (ISE-PIC)
- Primarily enterprise networks using Cisco's NAC and identity services.

---

## 🧰 TTPs (MITRE Mapping)

- **T1203:** Exploitation for Client Execution
- **T1133:** External Remote Services
- **T1190:** Exploit Public-Facing Application

---

## 📚 References

- <https://github.com/abrewer251/CVE-2025-20281-2-Citrix-ISE-RCE>
- <https://www.zoomeye.ai/searchResult?q=YXBwPSJDaXNjbyBJU0Ui>
- <https://github.com/advisories/GHSA-rc4f-42xm-hvjw>
- <https://github.com/advisories/GHSA-w8p2-wjjr-hr24>