CISA tilføjer Cisco ISE, PaperCut-sårbarheder til KEV-katalog

juli 28, 2025 • César Daniel Barreto

CISA Adds Three Known Exploited Vulnerabilities to Catalog cybersecurity vulnerability alert CVSS Unknown

On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services Engine (ISE) and one in PaperCut print-management software. Under Binding Operational Directive 22-01, federal civilian agencies were given until August 18, 2025 to remediate them.

The Cisco ISE vulnerabilities: unauthenticated root RCE

The two Cisco flaws are as severe as they come. CVE-2025-20281 og CVE-2025-20337 both carry the maximum CVSS score of 10.0, and both let an unauthenticated, remote attacker execute arbitrary code with rod privileges on Cisco ISE and the ISE Passive Identity Connector (ISE-PIC). One stems from insufficient input validation in an API endpoint; the other from unsafe deserialization. Only releases 3.3 and 3.4 are affected — but Cisco warns that earlier hot-fixes do not fully close the hole, so administrators must upgrade to ISE 3.3 Patch 7 eller 3.4 Patch 2. Cisco’s PSIRT confirmed attempted exploitation in the wild in late July, and a public proof-of-concept has since circulated.

The PaperCut NG/MF flaw

The third entry, CVE-2023-2533, is a cross-site request forgery (CSRF) vulnerability in PaperCut NG/MF rated CVSS 8.4. By luring an authenticated administrator with an active session into clicking a malicious link, an attacker can alter security settings and, under the right conditions, achieve remote code execution. Versions 21.2.0 through 22.0.12 are affected; the fix landed in 22.1.1 and later.

What to do now

If you run Cisco ISE 3.3 or 3.4, patch to the fixed builds immediately — unauthenticated, root-level remote code execution is a worst-case scenario, and exploit code is already public. PaperCut administrators should update to 22.1.1 or later and treat any unexpected configuration changes as a potential compromise. Because all three vulnerabilities now sit in CISA’s KEV catalog, active exploitation is ongoing, not theoretical — these are fixes to prioritize this week, not next quarter.

César Daniel Barreto, Cybersecurity Author at Security Briefing

César Daniel Barreto

César Daniel Barreto er en anerkendt cybersikkerhedsskribent og -ekspert, der er kendt for sin dybdegående viden og evne til at forenkle komplekse cybersikkerhedsemner. Med omfattende erfaring inden for netværks sikkerhed og databeskyttelse bidrager han regelmæssigt med indsigtsfulde artikler og analyser om de seneste cybersikkerhedstendenser og uddanner både fagfolk og offentligheden.

da_DKDanish