Cisco ISE Zero-Day Exploited for Malware Attack

13 Nov 2025

A critical vulnerability in Cisco Identity Services Engine (ISE), tracked as CVE-2025-20337, has been exploited by hackers to deploy malware. The flaw, noted with a maximum severity score of 10/10, allows attackers to execute arbitrary code on affected systems.

Vulnerability Exploitation

The issue stems from inadequate validation of user-supplied input, enabling pre-authentication remote code execution. Hackers used this flaw to install a custom web shell masked as a legitimate Cisco ISE component, named IdentityAuditAction.

  • Cisco ISE flaw identified as CVE-2025-20337
  • Allows unauthorized remote code execution
  • Weak input validation led to the vulnerability

Technical Details and Mechanism

The custom web shell exploited Tomcat server operations, leveraging Java reflection to manipulate running threads. It also used DES encryption with non-standard Base64 encoding for added stealth. Specific HTTP headers were required for access, enhancing the malware's concealment.

  • Web shell operated in-memory using Java
  • DES encryption implemented for stealth
  • Targeted Tomcat server's HTTP requests

Security Implications

Amazon's threat intelligence unit uncovered the widespread and indiscriminate use of this exploit. However, no specific threat actor or industry was identified as responsible. Entities relying on the Cisco ISE should assess their systems promptly to mitigate potential security risks.

Top charts for

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508630
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735697
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746789
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
497248
downloads

Comments (0)

No comments yet. Be the first to comment!