CISA Thêm Lỗ Hổng Cisco ISE, PaperCut Vào Danh Mục KEV
Tháng 7 28, 2025 • César Daniel Barreto

On July 28, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog — two in Cisco Identity Services Engine (ISE) and one in PaperCut print-management software. Under Binding Operational Directive 22-01, federal civilian agencies were given until August 18, 2025 to remediate them.
The Cisco ISE vulnerabilities: unauthenticated root RCE
The two Cisco flaws are as severe as they come. CVE-2025-20281 Và CVE-2025-20337 both carry the maximum CVSS score of 10.0, and both let an unauthenticated, remote attacker execute arbitrary code with root privileges on Cisco ISE and the ISE Passive Identity Connector (ISE-PIC). One stems from insufficient input validation in an API endpoint; the other from unsafe deserialization. Only releases 3.3 and 3.4 are affected — but Cisco warns that earlier hot-fixes do not fully close the hole, so administrators must upgrade to ISE 3.3 Patch 7 hoặc 3.4 Patch 2. Cisco’s PSIRT confirmed attempted exploitation in the wild in late July, and a public proof-of-concept has since circulated.
The PaperCut NG/MF flaw
The third entry, CVE-2023-2533, is a cross-site request forgery (CSRF) vulnerability in PaperCut NG/MF rated CVSS 8.4. By luring an authenticated administrator with an active session into clicking a malicious link, an attacker can alter security settings and, under the right conditions, achieve remote code execution. Versions 21.2.0 through 22.0.12 are affected; the fix landed in 22.1.1 and later.
What to do now
If you run Cisco ISE 3.3 or 3.4, patch to the fixed builds immediately — unauthenticated, root-level remote code execution is a worst-case scenario, and exploit code is already public. PaperCut administrators should update to 22.1.1 or later and treat any unexpected configuration changes as a potential compromise. Because all three vulnerabilities now sit in CISA’s KEV catalog, active exploitation is ongoing, not theoretical — these are fixes to prioritize this week, not next quarter.

César Daniel Barreto
César Daniel Barreto là một nhà văn và chuyên gia an ninh mạng được kính trọng, nổi tiếng với kiến thức sâu rộng và khả năng đơn giản hóa các chủ đề an ninh mạng phức tạp. Với kinh nghiệm sâu rộng về bảo mật mạng và bảo vệ dữ liệu, ông thường xuyên đóng góp các bài viết và phân tích sâu sắc về các xu hướng an ninh mạng mới nhất, giáo dục cả chuyên gia và công chúng.