Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Critical Cisco ISE AUTHPASS BYPASS NEFFE AS
Global Security

Critical Cisco ISE AUTHPASS BYPASS NEFFE AS

AdminBy AdminJune 5, 2025No Comments3 Mins Read
Cisco ISE Auth Bypass Flaw
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


05 June 2025Red LakshmananNetwork security / vulnerability

Cisco ise auth bypass bypass

Cisco has released security patches to address a critical security lack that affects the identity engine (ISE), which, if successfully used, can allow unauthorized actors to carry out malicious actions on sensitive systems.

Security defect, tracked as Cve-2025-20286Carries CVSS 9.9 out of 10.0. This has been described as static vulnerability of accounts.

“The vulnerability in Amazon Web Services (AWS), Microsoft Azure and Oracle Cloud Infrastructure (OCI) deploying Cisco Identiss Services Engine (ISE) can allow unauthorized, remote attackers to access sensitive data Violations of services within the affected systems “,” the company that has suffered – Note In advisory.

The creator of the network equipment attributed to Kentar Kentar from the Cybersecurity GMO for reports of the shortage, noted that he knew about the exploitation of the concept (POC). There is no evidence that in the wild it is angrily exploited.

Cybersecurity

Cisco said the problem follows that the credentials are incorrectly generated when Cisco ISE unfolds on cloud platforms, causing different deployments to share the same powers as long as the software release and the cloud platform are the same.

Otherwise, static credentials are characteristic of each issue and platforms, but do not act on the platforms. According to the company, all cases of Cisco ISE 3.1 release will have the same static credentials.

However, the credentials operating for access to release 3.1 will not be valid for access to the deployment of 3.2 on the same platform. In addition, Issue 3.2 on AWS will not have the same powers as I release 3.2 on Azure.

Successful exploitation of vulnerability can allow the attacker to extract user credentials from Cisco ISE deployment, and then use it to access Cisco ISE, deployed in other cloud conditions through unsecured ports.

This may eventually allow unauthorized access to sensitive data, executing limited administrative operations, changes to system configurations or service disruptions. Given this, Cisco ISE affects only in cases where the node of primary administration is expanded in the cloud. The primary nodes of the introduction in the local do not affect.

Cybersecurity

Affected by the following versions –

  • AWS – Cisco ISE 3.1, 3.2, 3.3 and 3.4
  • Azure – Cisco ISE 3.2, 3.3 and 3.4
  • OCI – CISCO ISE 3.2, 3.3 and 3.4

While there are no solutions to solve CVE-2025-20286, Cisco recommends users to restrict traffic to authorized administrators or launch the “Reset-Config ISE” command to reset users’ passwords to the new value. However, he notes that the team launch will reset Cisco ISE to the factory configuration.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025

Researchers in detail in detail decisively developing tactics as it expands its geographical volume

June 5, 2025

Iran related

June 5, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.