Cisco has released security updates to address three publicly exploitable flaws found in its Identity Services Engine (ISE) and Customer Collaboration Platform (CCP).
See also: Details of Cisco IOS XE flaw released publicly

The most serious of the three is a critical static credentials vulnerability, codenamed CVE-2025-20286, discovered by Kentaro Kawane of GMO Cybersecurity in Cisco ISE, the software that enforces user authentication policies and provides endpoint access control and network device management in enterprise environments.
The vulnerability is caused by improper credential generation when deploying Cisco ISE in cloud, resulting in shared credentials being used across different installations. Unauthorized attackers can exploit the issue by extracting user credentials from Cisco ISE installations in the cloud and using them to access other installations in different cloud environments. However, as Cisco explained, exploiting the vulnerability is only possible if the Primary Administration is deployed in the cloud.
Cisco added that the following ISE installations are not vulnerable to attacks:
- All on-premises installations, regardless of form factor, when the required files have been installed from the Cisco Software Download Center (either via ISO or OVA). This includes both physical devices and virtual machines of various types.
- Installing ISE on Azure VMware Solution (AVS)
- Installing ISE on Google Cloud VMware Engine
- Installing ISE on VMware Cloud on AWS
- Hybrid ISE deployments, where all management roles (Primary and Secondary Administration) are located in an on-premises environment, while other roles may be hosted in the cloud.
See also: Cisco patches high-severity DoS vulnerability

The company advises administrators who are either still waiting for a hotfix or cannot apply it immediately, to run the application reset-config ise command on the cloud node with the Cisco ISE Primary Administration role to reset user passwords to a new value
However, administrators should be aware that this command resets Cisco ISE to factory settings and that restoring backups will also restore the original credentials.
The other two vulnerabilities that were fixed and for which proof-of-concept exploit code is available are:
- An arbitrary file upload vulnerability (CVE-2025-20130) in Cisco ISE.
- An information disclosure vulnerability (CVE-2025-20129) in Cisco Customer Collaboration Platform (formerly Cisco SocialMiner).
In September, Cisco patched another vulnerability in ISE, involving command injection with public exploit code, which allowed attackers to gain root privileges on unpatched systems.
See also: Cisco patches 35 vulnerabilities in various products
Using Cisco ISE in cloud infrastructures can pose additional risks, especially when proper credential creation and management is not ensured. The CVE-2025-20286 vulnerability highlights how critical it is to follow strict security policieswhen installing and configuring such systems, especially in the cloud, where shared resource use and automation can lead to recurring errors (such as shared credentials).
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
