Cisco Identity Services Engine XML External Entity Processing Information Disclosure Vulnerability
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information...
Date: December 30, 2025 Revision Date Changes 1.0 December 30, 2025 Initial release 1.1 February 3, 2026 Updated Required Configuration for Exploitation The CVE-ID tracking this issue: CVE-2025-7048 CVSS:3.1 Base Score 4.3 (CVSS:3.1/AV:A/AC:L/PR:N/UI...
Date: December 23, 2025 Revision Date Changes 1.0 July 5, 2020 Initial release 1.1 December 23, 2025 Updated to Arista Format NOTICE: VeloCloud is now an Arista product.Arista Networks has reposted this advisory that was originally posted by VMware...