IP Access Restriction Bypass in Cisco ISE and ISE-PIC
CVE-2025-20285

4.1MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
16 July 2025

Badges

👾 Exploit Exists

What is CVE-2025-20285?

A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC can enable an authenticated remote attacker to bypass established IP access controls, potentially allowing unauthorized access from blocked IP addresses. This weakness stems from inadequate enforcement of access controls within the IP Access Restriction feature. An attacker with valid administrative credentials may exploit this issue by logging in to the device's API from an unauthorized source IP address, effectively gaining access that should otherwise be denied. Organizations are advised to ensure proper access control mechanisms to mitigate this risk.

Affected Version(s)

Cisco Identity Services Engine Software 3.1.0

Cisco Identity Services Engine Software 3.1.0 p1

Cisco Identity Services Engine Software 3.1.0 p3

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20285 : IP Access Restriction Bypass in Cisco ISE and ISE-PIC