Cisco on Wednesday published ten security advisories, describing more than a dozen vulnerabilities in products , including two high-severity ones in the Identity Services Engine (ISE) and Unified Intelligence Center that could allow DoS.
See also: Google fixes vulnerability in Quick Share that causes DoS

The flaw in ISE, with identifier CVE-2025-20152 , affects the RADIUS message processing function and can be exploited remotely , without authentication, causing ISE to restart and leading to a denial of service (DoS) condition.
The company also fixed another high-severity issue in Unified Intelligence Center, CVE -2025-20113, which could allow a certified attacker to gain elevated administrator privileges for a limited set of operations on the vulnerable system. This flaw was fixed along with CVE-2025-20114, a medium-severity vulnerability that can be exploited for privilege escalation.
See also: OpenSSH flaws expose SSH servers to MiTM and DoS attacks
Medium severity vulnerabilities were also patched in Webex, Webex Meetings, Secure Network Analytics Manager, Secure Network Analytics Virtual Manager, ISE, Duo, Unified Communications and Contact Center Solutions, and Unified Contact Center Enterprise (CCE) products.

Successful exploitation of these vulnerabilities could lead to XSS attacks, corruption of cached HTTP responses, arbitrary command execution, false results in analytics reports, arbitrary command injection, privilege escalation, and data tampering.
Cisco says that, to date, there is no evidence that any of these vulnerabilities have been actively exploited. More information is available on Cisco's security advisories page
See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks
Related to the above is how critical it is to regularly update and manage vulnerabilities in IT systems. Cisco's announcements show that even large technology providers with mature development processes can identify and fix significant security gaps in their products.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
