#cve-2025-20337

[ follow ]
Information security
fromTheregister
1 week ago

Amazon: Cisco, Citrix 0-days indicate 'advanced' attacker

An advanced attacker used CitrixBleed 2 and an undocumented, max-severity Cisco ISE vulnerability as zero-days to deploy custom malware and achieve remote root code execution.
fromThe Hacker News
4 months ago

Cisco Warns of Critical ISE Flaw Allowing Unauthenticated Attackers to Execute Root Code

Multiple vulnerabilities in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit these vulnerabilities.
Information security
[ Load more ]