PT-2025-22379 · Cisco · Cisco Identity Services Engine
Published
2025-04-04
·
Updated
2025-07-11
·
CVE-2025-20152
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Identity Services Engine (ISE) version 3.4
Description
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a specific authentication request to a network access device (NAD) that uses Cisco ISE for authentication, authorization, and accounting (AAA). A successful exploit could allow the attacker to cause Cisco ISE to reload.
Recommendations
For Cisco Identity Services Engine (ISE) version 3.4, immediate patching is recommended to prevent attackers from triggering a DoS via crafted RADIUS requests, causing system reboots. As a temporary workaround, consider restricting access to the RADIUS message processing feature until a patch is available. Avoid using the vulnerable RADIUS implementation in the affected API endpoint until the issue is resolved.
Fix
DoS
LPE
Out of bounds Read
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Identity Services Engine