IP Access Restriction Bypass in Cisco ISE and ISE-PIC
CVE-2025-20285
What is CVE-2025-20285?
A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC can enable an authenticated remote attacker to bypass established IP access controls, potentially allowing unauthorized access from blocked IP addresses. This weakness stems from inadequate enforcement of access controls within the IP Access Restriction feature. An attacker with valid administrative credentials may exploit this issue by logging in to the device's API from an unauthorized source IP address, effectively gaining access that should otherwise be denied. Organizations are advised to ensure proper access control mechanisms to mitigate this risk.
Affected Version(s)
Cisco Identity Services Engine Software 3.1.0
Cisco Identity Services Engine Software 3.1.0 p1
Cisco Identity Services Engine Software 3.1.0 p3