PT-2023-4875 · Cisco · Cisco Identity Services Engine

Published

2023-09-06

·

Updated

2024-02-04

·

CVE-2023-20243

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) (affected versions not specified)
Description The issue is related to improper handling of certain RADIUS accounting requests in the RADIUS message processing feature of Cisco Identity Services Engine (ISE). This could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets by sending a crafted authentication request to a network access device (NAD) that uses Cisco ISE for authentication, authorization, and accounting (AAA), or by sending a crafted RADIUS accounting request packet to Cisco ISE directly if the RADIUS shared secret is known. A successful exploit could result in authentication or authorization timeouts and deny legitimate users access to the network or service. Clients already authenticated to the network would not be affected.
Recommendations To recover the ability to process RADIUS packets, a manual restart of the affected Policy Service Node (PSN) may be required. As a temporary workaround, consider restricting access to the RADIUS message processing feature until a patch is available. Avoid using the vulnerable RADIUS accounting request packet until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Improper Authentication

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2023-05366
CVE-2023-20243

Affected Products

Cisco Identity Services Engine