APromptRiskDBThreat intelligence atlas
AI Vulnerability Context

CVE-2025-20337 - Cisco Identity Services Engine

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

AI Vulnerability ContextCISA KEVCisco

Record summary

A quick snapshot of what this page covers.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEV
CVE ID
CVE-2025-20337
Vendor/project
Cisco
Product
Identity Services Engine
Vulnerability name
Cisco Identity Services Engine Injection Vulnerability
Date added
2025-07-28
Due date
2025-08-18
Known ransomware campaign use
Unknown
CWE-74

Exploit context

What the vulnerability is about.

No description available. The source record only contains identifiers and metadata.

Source

Where this page information comes from.