Cisco ISE Authenticated Sensitive Info Disclosure via Web Interface
CVE-2025-20305 Published on November 5, 2025
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could exploit this vulnerability by performing actions where the results should only be viewable to a high-privileged user. A successful exploit could allow the attacker to view passwords that are normally not visible to read-only administrators.
Vulnerability Analysis
CVE-2025-20305 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
Insufficient Granularity of Access Control
The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
Products Associated with CVE-2025-20305
stack.watch emails you whenever new vulnerabilities are published in Cisco Identity Services Engine Software or Cisco Identity Services Engine. Just hit a watch button to start following.
Affected Versions
Cisco Identity Services Engine Software:- Version 3.1.0 is affected.
- Version 3.1.0 p1 is affected.
- Version 3.1.0 p3 is affected.
- Version 3.1.0 p2 is affected.
- Version 3.1.0 p4 is affected.
- Version 3.1.0 p5 is affected.
- Version 3.1.0 p6 is affected.
- Version 3.1.0 p7 is affected.
- Version 3.1.0 p8 is affected.
- Version 3.1.0 p9 is affected.
- Version 3.1.0 p10 is affected.
- Version 3.2.0 is affected.
- Version 3.2.0 p1 is affected.
- Version 3.2.0 p2 is affected.
- Version 3.2.0 p3 is affected.
- Version 3.2.0 p4 is affected.
- Version 3.2.0 p5 is affected.
- Version 3.2.0 p6 is affected.
- Version 3.2.0 p7 is affected.
- Version 3.3.0 is affected.
- Version 3.3 Patch 2 is affected.
- Version 3.3 Patch 1 is affected.
- Version 3.3 Patch 3 is affected.
- Version 3.3 Patch 4 is affected.
- Version 3.3 Patch 5 is affected.
- Version 3.3 Patch 6 is affected.
- Version 3.3 Patch 7 is affected.
- Version 3.4.0 is affected.
- Version 3.4 Patch 1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.