Cisco ISE enableStrongSwanTunnel Unauthenticated Remote Code Execution Webapp Exploit

This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Send an unauthenticated serialized Java String array whose first element contains a shell injection. Literal spaces are replaced with the Bash Internal Field Separator so the command survives Java Runtime.exec tokenization. Compare a baseline request with a delayed request to verify blind command execution as root inside the privileged strongswan-container. Attempt to escape the container through a writable cgroup v1 release_agent interface. The module resolves the overlay upper directory for the container root, writes a self-deleting host script, creates a child cgroup with notify_on_release enabled, and triggers the release agent. Create a marker on the persistent ISE volume and use a second time-delay probe to verify that commands execute as root on the underlying ISE host. If host execution cannot be verified, continue with root command execution inside strongswan-container and clearly report that restricted execution context. Deploy a blind OSCI agent by default. OSCI commands are relaunched through the vulnerable API and execute as root in the verified context, but stdout and stderr are not returned by the endpoint. When requested through Install OS Agent, optionally serve, download, and execute a Linux Core Impact agent with root privileges.
Product Name