Serias vulnerabilidades en Cisco Ish y UIC

On May 22, 2025, Cisco announced critical security updates for two of its products: the Cisco Identity Services Engine (ISE) and Cisco Unified Intelligence Center (UIC). Two significant vulnerabilities were identified and assigned CVE identifiers: CVE-2025-20152 and CVE-2025-20113. The vulnerabilities received CVSS severity scores of 8.6 and 7.1, respectively.

The first vulnerability, CVE-2025-20152, poses a serious risk as it allows remote attacks that could render the Cisco ISE inoperable. This could significantly disrupt organizations relying on ISE for identity and access management. The second vulnerability, CVE-2025-20113, involves privilege escalation within the Cisco UIC, potentially allowing unauthorized users to gain elevated access privileges, which could compromise the system’s security.

Cisco has confirmed that, as of the latest updates, there are no known active exploits leveraging these vulnerabilities, which indicates that they have not yet been targeted by malicious actors.

Affected Products

The vulnerabilities affect the following Cisco products:

  • Cisco Identity Services Engine 3.4 (versions prior to 3.3 are not vulnerable)
  • Cisco Unified Intelligence Center 12.5
  • Cisco Unified Intelligence Center 12.6
  • Cisco Unified CCX 12.5 SU3 and earlier versions

Additionally, the security advisory mentions that there are other affected Cisco products, urging users to refer to the Cisco Security Advisory for comprehensive information.

Recommendations

In light of these vulnerabilities, CERT-SE recommends that users immediately update their vulnerable products according to the manufacturer’s guidelines. This is a critical step in maintaining the integrity and security of their systems.

For further details on the vulnerabilities, users can reference the official National Institute of Standards and Technology (NIST) vulnerability databases linked to the CVEs, along with Cisco’s own security advisories for both the ISE and UIC:

  1. CVE-2025-20152 NVD Detail
  2. CVE-2025-20113 NVD Detail
  3. Cisco Security Advisory for ISE
  4. Cisco Security Advisory for UIC
  5. Cisco Publications Listing

In summary, these vulnerabilities highlight the importance of ongoing security vigilance and prompt action to mitigate risks associated with software vulnerabilities in critical infrastructure. Organizations using the affected Cisco products should prioritize updating their systems to protect against potential future attacks exploiting these vulnerabilities.

Enlace de la fuente, haz clic para tener más información

Alertas y noticias de seguridad de la información

Contacta

Contacta con nosotros para obtener soluciones integrales en IT y seguridad de la información

Estamos encantados de responder cualquier pregunta que puedas tener, y ayudarte a determinar cuáles de nuestros servicios se adaptan mejor a tus necesidades.

Nuestros beneficios:
¿Qué sucede a continuación?
1

Programamos una llamada según tu conveniencia.

2

Realizamos una reunión de descubrimiento y consultoría.

3

Preparamos una propuesta.

Agenda una consulta gratuita