Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cisco’s CVE-2025-20286 affects specific cloud-hosted Cisco Identity Services Engine (ISE) deployments, not AWS, Azure or Oracle Cloud Infrastructure (OCI) accounts generally. The risk depends on the ISE release, cloud platform and location of the Primary Administration node. Cisco says a software update addresses the flaw; the advisory lists no workaround that fixes it.

What the Cisco ISE vulnerability does

Cisco said credentials were improperly generated during deployment, causing qualifying ISE instances to share static credentials when they used the same software release and cloud platform. For example, Cisco said ISE 3.1 instances on AWS shared credentials; those credentials did not apply to ISE 3.2 on AWS or ISE 3.2 on Azure.

An unauthenticated remote attacker who obtained the credentials from a cloud-deployed ISE instance could use them to access other ISE deployments through unsecured ports. Cisco describes possible access to sensitive data, limited administrative operations, configuration changes and service disruption. The advisory does not say that customers’ underlying cloud accounts were compromised.

Cisco assigned CVE-2025-20286 a CVSS base score of 9.9 in its advisory first published June 4, 2025. A CVSS score measures vulnerability severity; it is not a probability of exploitation or a count of affected systems. Cisco’s security advisory credits Kentaro Kawane of GMO Cybersecurity by Ierae with reporting the issue.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which Cisco ISE releases and cloud deployments are affected?

Cisco’s advisory identifies these releases in the default configuration. It says the deployment is affected when its Primary Administration node is deployed in the cloud. If that node is on-premises, Cisco says the deployment is not affected.

Cloud platform Affected ISE releases in default configuration
AWS 3.1, 3.2, 3.3 and 3.4
Microsoft Azure 3.2, 3.3 and 3.4
Oracle Cloud Infrastructure (OCI) 3.2, 3.3 and 3.4

These platform and version details are from Cisco’s advisory for CVE-2025-20286. Confirm the exact release and topology against the advisory rather than relying on the version number alone.

Rank #2
Cisco Meraki MX67-HW Wired Network Security/Firewall - Appliance Only
  • Stateful firewall throughput: 450 Mbps.
  • Recommended maximum clients: 50.
  • Managed centrally over the web. Classifies applications, users and devices.
  • Layer 7 application visibility and traffic shaping. Application prioritization.
  • Dimensions: 9.4 x 5.1 x 1.1 inches. Weight: 1.54 lbs (24.69 ounces).

Deployments Cisco lists as not vulnerable

Cisco says the following deployment types are not vulnerable:

  • On-premises Cisco ISE installations.
  • Azure VMware Solution.
  • Google Cloud VMware Engine.
  • VMware cloud in AWS.
  • Certain hybrid deployments in which both administrator personas are on-premises.

Because Cisco distinguishes these cases by deployment architecture, verify where the Primary Administration node and administrator personas are located before deciding that a deployment is outside the advisory’s scope.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
  • 10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover
  • Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
  • Recommended maximum clients: 50, Layer 7 application visibility and traffic shaping
  • Automatic firmware upgrades and security patches, VLAN support and DHCP services
  • Includes 100W DC Power Supply, requires Enterprise or Advanced Security License

How to check whether your deployment is affected

  1. Identify the cloud platform hosting the ISE deployment: AWS, Azure or OCI.
  2. Check the exact Cisco ISE release and compare it with the affected-release table above.
  3. Confirm whether the Primary Administration node is deployed in the cloud or on-premises.
  4. Check whether the architecture matches one of Cisco’s listed not-vulnerable deployment types.
  5. Determine whether Cisco’s applicable fixed software has been installed. If you cannot confirm any of these details, use Cisco’s advisory and support channels to validate the deployment before treating it as unaffected.

What fixes Cisco provides

Cisco says software updates address CVE-2025-20286. The advisory’s fixed-software table lists a hot fix applicable to releases 3.1 through 3.4. It identifies ISE 3.3P8 as the first fixed release for 3.3 and 3.4P3 as the first fixed release for 3.4. For 3.1 and 3.2, Cisco says to migrate to a fixed release but does not name a first fixed release in those rows; do not infer a specific target from the 3.3 or 3.4 entries. Cisco says releases 3.0 and earlier are not affected.

Customers with service contracts should obtain security fixes through their usual Cisco update channels. Customers without service contracts who cannot obtain the fixed software through their point of sale are directed to contact Cisco TAC, with the product serial number and advisory URL available. Cisco says downloads are limited to properly licensed customers and recommends checking memory and configuration support before upgrading.

Rank #4
Sale
Cisco Meraki MX68CW-HW Network Security Firewall Appliance w/ Power Adapter & Antennas [Unclaimed & No License] (Renewed)
  • MX68CW include a SIM slot and internal LTE modem. This integrated functionality removes the need for external hardware and allows for cellular visibility and configuration within the Meraki dashboard.
  • One CAT 6, 300 Mbps LTE modem + 1 x Nano SIM slot (4ff form factor) +++ Global coverage with individual orderable SKUs for North America and worldwide
  • MX68CW include two ports with 802.3at (PoE+). This built-in power capability removes the need for additional hardware to power critical branch devices.
  • WAN: 2 GbE, one Cat 6 modem, one USB (cellular failover) + LAN: 10 GbE (two PoE+); Wi-Fi: 802.11ac Wave 2 + 600 Mbps firewall throughput
  • Supports up to 50 users + 300 Mbps site-to-site VPN throughput

Fresh-install instructions and backup caution

For fresh installations, Cisco instructs administrators to run application reset-config ise only on the cloud Primary Administration node to reset user passwords to a new value. Secondary nodes do not need the command, and it is unnecessary when the Primary Administration persona is on-premises. Cisco warns that the command resets ISE to factory configuration, so it should be used only under the stated conditions and with an understanding of its effect.

Cisco warns that restoring a configuration backup made before the fix can restore old credentials. It recommends taking a new backup after installing the fix. If an old backup was restored, Cisco says the hot fix must be removed and reinstalled.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Cisco 3000 Network Security/Firewall Appliance
  • 2 X 10/100/1000 + 2 X GIGABIT SFP
  • CHASIS 64 GB MSATA
  • DC POWER
  • DIN RAIL MOUNTABLE
  • INDUSTRIAL SECURITY APPLIANCE
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Mitigations while arranging the software fix

Cisco describes two mitigations: restrict source IP addresses through cloud security groups, and allow administrator source IP addresses in the Cisco ISE UI. These measures are not substitutes for the software fix, and Cisco says the advisory has no workaround that addresses the vulnerability. It also warns that mitigations can affect functionality or performance, so evaluate their applicability and impact in the specific environment before applying them.

What Cisco said about exploitation

In an update to the advisory on June 5, 2025, Cisco PSIRT said proof-of-concept exploit code was available and that it was not aware of malicious use of the vulnerability. Those statements describe Cisco’s knowledge at that time, not current threat activity.

Quick Recap

Bestseller No. 2
Cisco Meraki MX67-HW Wired Network Security/Firewall - Appliance Only
Cisco Meraki MX67-HW Wired Network Security/Firewall - Appliance Only
Stateful firewall throughput: 450 Mbps.; Recommended maximum clients: 50.; Managed centrally over the web. Classifies applications, users and devices.
$340.00
Bestseller No. 3
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover; Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
$620.00
SaleBestseller No. 4
Bestseller No. 5
Cisco 3000 Network Security/Firewall Appliance
Cisco 3000 Network Security/Firewall Appliance
2 X 10/100/1000 + 2 X GIGABIT SFP; CHASIS 64 GB MSATA; DC POWER; DIN RAIL MOUNTABLE; INDUSTRIAL SECURITY APPLIANCE
$5,373.62

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.