Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Critical Open VSX -no -register exposes millions of developers for supply chain attacks

June 26, 2025

The new FileFix method is a threat

June 26, 2025

RCE Critical Disadvantages in Cisco ISE and ISE-PIC allow unauthorized attackers to access the roots

June 26, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » RCE Critical Disadvantages in Cisco ISE and ISE-PIC allow unauthorized attackers to access the roots
Global Security

RCE Critical Disadvantages in Cisco ISE and ISE-PIC allow unauthorized attackers to access the roots

AdminBy AdminJune 26, 2025No Comments2 Mins Read
Unauthenticated Attackers to Gain Root Access
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 26, 2025Red LakshmananVulnerability, network safety

Non -false attackers to get root access

Cisco is liberated Updates to eliminate two deficiencies of the maximum capacity in the identity engine (ISE) and ISE a passive identity connector (ISE-PIC) that can allow an unauthorized attacker to perform arbitrary commands as a root user.

The vulnerabilities assigned to the CVE-2015-20281 and CVE-2015-20282 IDs are given a CVS mark for 10.0 each. Description of defects below –

  • Cve-2025-20281 – Invalid vulnerability of the remote code that affects
  • Cve-2015-20282 – Invalid vulnerability of the remote code that affects

Cisco said that the CVE-2025-20281 is the result of insufficient input check that the user can use by sending an API request to receive increased privileges and launching commands.

Cybersecurity

Unlike this, the CVE-2025-20282 stems from the lack of a file check, which otherwise prevent the location of the downloaded files into the privileged directory.

“Successful feat can allow the attacker to store malicious files in the affected system and then execute an arbitrary code or get root privileges in the system,” Cisco said.

The network equipment provider said there were no solutions that solve problems. Disadvantages were considered in the versions below –

  • Cve-2025-20281 .
  • Cve-2015-20282 -Cisco ise or ISE-PIC 3.4 Patch 2 (ISE-APPLY-CSCWO99449_3.4.608_PATCH1-sPA.TAR.GZ

The company counted Bobby Goold with Trend Micro Zero Day Initiative and Kentaro Kawane from GMO cybersecurity for Cve-2025-20281. Kawane which previously reported Cve-2025-20286 (CVSS assessment: 9.9), also recognized for the Cve-2025-20282 report.

Although there is no evidence that vulnerabilities have been used in the wild, it is important that users move quickly to apply fixes to protect against potential threats.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Critical Open VSX -no -register exposes millions of developers for supply chain attacks

June 26, 2025

The new FileFix method is a threat

June 26, 2025

Why is built -in protection insufficient for modern data sustainability

June 26, 2025

Iranian APT35 hackers are oriented

June 26, 2025

Cyber-Cyber ​​Use open source tools to compromise financial institutions across Africa

June 26, 2025

CISA adds 3 flaws to KEV directory, affecting AMI Megarac, D-Link, Fortinet

June 26, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Critical Open VSX -no -register exposes millions of developers for supply chain attacks

June 26, 2025

The new FileFix method is a threat

June 26, 2025

RCE Critical Disadvantages in Cisco ISE and ISE-PIC allow unauthorized attackers to access the roots

June 26, 2025

Why is built -in protection insufficient for modern data sustainability

June 26, 2025

Iranian APT35 hackers are oriented

June 26, 2025

Cyber-Cyber ​​Use open source tools to compromise financial institutions across Africa

June 26, 2025

CISA adds 3 flaws to KEV directory, affecting AMI Megarac, D-Link, Fortinet

June 26, 2025

WhatsApp adds resumes that run on AI, for faster preview chat

June 26, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Critical Open VSX -no -register exposes millions of developers for supply chain attacks

June 26, 2025

The new FileFix method is a threat

June 26, 2025

RCE Critical Disadvantages in Cisco ISE and ISE-PIC allow unauthorized attackers to access the roots

June 26, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.