CISA Aggiunge le Vulnerabilità di Cisco ISE e PaperCut al Catalogo KEV
Luglio 28, 2025 • César Daniel Barreto

On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services Engine (ISE) and one in PaperCut print-management software. Under Binding Operational Directive 22-01, federal civilian agencies were given until August 18, 2025 to remediate them.
The Cisco ISE vulnerabilities: unauthenticated root RCE
The two Cisco flaws are as severe as they come. CVE-2025-20281 e CVE-2025-20337 both carry the maximum CVSS score of 10.0, and both let an unauthenticated, remote attacker execute arbitrary code with root privileges on Cisco ISE and the ISE Passive Identity Connector (ISE-PIC). One stems from insufficient input validation in an API endpoint; the other from unsafe deserialization. Only releases 3.3 and 3.4 are affected — but Cisco warns that earlier hot-fixes do not fully close the hole, so administrators must upgrade to ISE 3.3 Patch 7 o 3.4 Patch 2. Cisco’s PSIRT confirmed attempted exploitation in the wild in late July, and a public proof-of-concept has since circulated.
The PaperCut NG/MF flaw
The third entry, CVE-2023-2533, is a cross-site request forgery (CSRF) vulnerability in PaperCut NG/MF rated CVSS 8.4. By luring an authenticated administrator with an active session into clicking a malicious link, an attacker can alter security settings and, under the right conditions, achieve remote code execution. Versions 21.2.0 through 22.0.12 are affected; the fix landed in 22.1.1 and later.
What to do now
If you run Cisco ISE 3.3 or 3.4, patch to the fixed builds immediately — unauthenticated, root-level remote code execution is a worst-case scenario, and exploit code is already public. PaperCut administrators should update to 22.1.1 or later and treat any unexpected configuration changes as a potential compromise. Because all three vulnerabilities now sit in CISA’s KEV catalog, active exploitation is ongoing, not theoretical — these are fixes to prioritize this week, not next quarter.

Cesare Daniele Barreto
César Daniel Barreto è uno stimato scrittore ed esperto di cybersecurity, noto per la sua approfondita conoscenza e per la capacità di semplificare argomenti complessi di sicurezza informatica. Con una vasta esperienza nel campo della sicurezza delle reti e della protezione dei dati, contribuisce regolarmente con articoli e analisi approfondite sulle ultime tendenze in materia di tendenze della cybersecurity, educando sia i professionisti che il pubblico.