Vulnerabilidades críticas en Cisco Identity Services Engine

Cisco has issued a warning regarding two critical vulnerabilities affecting its Identity Services Engine (ISE), which is crucial for identity management. The vulnerabilities identified as CVE-2025-20124 and CVE-2025-20125 have received high severity scores of 9.9 and 9.1, respectively, on the CVSS scale, which ranges from 0 to 10. These vulnerabilities can be exploited independently and could allow an attacker to execute arbitrary commands remotely, as well as gain escalated privileges on the affected devices. However, it is necessary for the attacker to have valid administrative authentication credentials to exploit these vulnerabilities.

In response to these security risks, Cisco has provided a security update to address the vulnerabilities. The affected products include the Cisco ISE and the Cisco ISE Passive Identity Connector (ISE-PIC).

To mitigate the risks posed by these vulnerabilities, CERT-SE has strongly recommended that users of the affected products update their systems as soon as possible and adhere to the guidance provided by Cisco.

For further information, Cisco has published additional details on its security advisory page. Users are encouraged to take immediate action to protect their systems from potential security threats related to these vulnerabilities.

Enlace de la fuente, haz clic para tener más información

Artículos y alertas de seguridad

Consultar más contenidos y alertas

Alertas y noticias de seguridad de la información

Contacta

Contacta con nosotros para obtener soluciones integrales en IT y seguridad de la información

Estamos encantados de responder cualquier pregunta que puedas tener, y ayudarte a determinar cuáles de nuestros servicios se adaptan mejor a tus necesidades.

Nuestros beneficios:
¿Qué sucede a continuación?
1

Programamos una llamada según tu conveniencia.

2

Realizamos una reunión de descubrimiento y consultoría.

3

Preparamos una propuesta.

Agenda una consulta gratuita