Cisco Identity Services Engine Authorization Bypass Vulnerability
TL;DR ๐
- A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an external identity provider. An attacker could exploit this vulnerability by submitting a series ofโฆ
- No fixed release listed yet; apply mitigations and monitor.
- Workarounds are documented in the advisory.
- CVEs: CVE-2025-20264.
What happened ๐ต๏ธโโ๏ธ
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.
This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an external identity provider. An attacker could exploit this vulnerability by submitting a series of specific commands to an affected device. A successful exploit could allow the attacker to modify a limited number of system settings, including some that would result in a system restart. In single-node Cisco ISE deployments, devices that are not authenticated to the network will not be able to authenticate until the Cisco ISE system comes back online.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Affected products ๐ฅ๏ธ
At the time of publication, this vulnerability affected Cisco ISE if it used SAML SSO integration with an external identity provider for user creation.
For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.
Fixed software ๐ง
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 3.1 and earlier | Migrate to a fixed release. | |
| 3.2 | 3.2P8 (Nov 2025) | |
| 3.3 | 3.3P5 | |
| 3.4 | 3.4P2 | |
| 1.0 | Initial public release. |
Workarounds ๐งฏ
There are no workarounds that address this vulnerability.
Risk in context ๐ฏ
Use vendor CVSS for prioritization. Consider exposure and asset criticality.
Fast facts โก
- Advisory: cisco-sa-ise-auth-bypass-mVfKVQAU
- Initial release: 2025-06-25T16:00:00 UTC
- Last updated: 2025-06-25T16:00:00 UTC
For leadership ๐งญ
Executive summary. Cisco ISE deployments using SAML SSO for admin user creation have a gap in authorisation checks that lets a logged-in attacker alter system settings and force a restart, which on single-node setups halts network authentication until it recovers. There is no workaround, so this needs a patch scheduled rather than a stopgap applied.
Why it matters:
- The flaw sits in ISE’s web-based management interface and only affects accounts created through SAML SSO integration with an external identity provider, so any ISE deployment relying on federated admin logins is in scope.
- An attacker who already has an authenticated session can push commands that change a limited set of system settings, including ones that force a restart.
- On single-node ISE deployments, a forced restart means network devices cannot authenticate until ISE comes back online, directly affecting NAC-dependent network access.
- Cisco has stated there are no workarounds, so exposure persists on affected trains until the fixed release is installed.
Now / Next / Later:
- Now: Identify every Cisco ISE node using SAML SSO for admin user creation and check whether it runs 3.1 or earlier, 3.2 before P8, 3.3 before P5, or 3.4 before P2.
- Next: Schedule an upgrade to the first fixed release for each affected train (3.2P8, 3.3P5, 3.4P2, or migrate off 3.1 and earlier) during the next maintenance window, prioritising single-node deployments given the restart-induced authentication outage risk.
- Later: Review who holds SAML SSO admin roles on ISE and tighten provisioning so federated accounts get only the administrative scope they need, reducing the impact of any future authorisation gaps.