newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Faults in Critical Cisco ISE authentication affect cloud deployments on AWS, Azure, and OCI
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Faults in Critical Cisco ISE authentication affect cloud deployments on AWS, Azure, and OCI
Technology

Faults in Critical Cisco ISE authentication affect cloud deployments on AWS, Azure, and OCI

June 8, 2025 3 Min Read
Share
Faults in Critical Cisco ISE authentication affect cloud deployments on AWS, Azure, and OCI
SHARE

Cisco has released security patches to address critical security flaws affecting the Identity Services Engine (ISE).

Security flaws tracked as an AS CVE-2025-20286carry a CVSS score of 9.9 out of 10.0. It is said to be a static credential vulnerability.

“Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments allow ruthless remote attackers to access sensitive data, perform restricted management operations, modify system configurations, and denial services within the system.”

The networking equipment manufacturer, who praised GMO Cybersecurity’s Kentaro Kawane for reporting the flaws, noted that they are aware of the existence of proof of concept (POC) exploits. There is no evidence that it was misused in the wild.

Cisco said the issue stems from the fact that when Cisco ISE is deployed on a cloud platform, the credentials are generated improperly, and different deployments share the same credentials as long as the software release and cloud platform are the same.

Put another way, static credentials are specific to each release and platform, but not valid across platforms. As the company emphasizes, all instances of Cisco ISE Release 3.1 on AWS have the same static credentials.

However, the credentials valid for accessing a Release 3.1 deployment are not valid for accessing a Release 3.2 deployment on the same platform. Additionally, AWS release 3.2 does not have the same credentials as Azure release 3.2.

The successful exploitation of the vulnerability allows an attacker to extract user credentials from a Cisco ISE cloud deployment and use it to access Cisco ISE deployed to other cloud environments through a specific port.

See also  New research uses attachment theory to decipher relationships with humans

This ultimately allows for unauthorized access to sensitive data, perform limited administrative operations, modify system configuration, or disruption of services. That said, Cisco ISE is only affected if the primary management node is deployed in the cloud. Primary management nodes that are on-premises are not affected.

The following versions are affected –

  • AWS -Cisco ISE 3.1, 3.2, 3.3, and 3.4
  • Azure – Cisco ISE 3.2, 3.3, and 3.4
  • OCI – Cisco ISE 3.2, 3.3, and 3.4

Although there is no workaround to address CVE-2025-20286, Cisco recommends that users either restrict traffic to certified administrators or run the “Application Reset Configuration ISE” command to reset the user password to the new value. However, it has been pointed out that running the command will reset Cisco ISE to its factory configuration.

Share This Article
Facebook Twitter Copy Link
Previous Article Former Lionsgate top exec Jason Constantine dies aged 55 Former Lionsgate top exec Jason Constantine dies aged 55
Next Article Shaquille O’Neal criticized lightning after stoking victory in Game 1 of the NBA Finals Shaquille O’Neal criticized lightning after stoking victory in Game 1 of the NBA Finals
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code
Technology

Important 10-year-old round cube webmail bug allows authenticated users to execute malicious code

2 Min Read
New Linux flaws allow password hash theft via core dumps in Ubuntu, Rhel, Fedora
Technology

New Linux flaws allow password hash theft via core dumps in Ubuntu, Rhel, Fedora

4 Min Read
“Time to uninstall Google Chrome” Warns Cybersecurity Experts
Technology

“Time to uninstall Google Chrome” Warns Cybersecurity Experts

6 Min Read
AI Liability Insurance: Next Steps to Protect Your Business from AI Failure
Technology

AI Liability Insurance: Next Steps to Protect Your Business from AI Failure

13 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?