CVE-2025-20337 | Cisco Identity Services Engine Software 3.3.0/3.4.0 API injection (cisco-sa-ise-unauth-rce-ZAd2GnJ6 / EUVD-2025-21708)
A vulnerability, which was classified as problematic, was found in Cisco Identity Services Engine Software and ISE Passive Identity Connector 3.3.0/3.4.0. Affected is an unknown function of the component API Handler. The manipulation leads to injection.
This vulnerability is traded as CVE-2025-20337. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.