PT-2025-22379 · Cisco · Cisco Identity Services Engine

Published

2025-04-04

·

Updated

2025-07-11

·

CVE-2025-20152

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco Identity Services Engine (ISE) version 3.4
Description A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a specific authentication request to a network access device (NAD) that uses Cisco ISE for authentication, authorization, and accounting (AAA). A successful exploit could allow the attacker to cause Cisco ISE to reload.
Recommendations For Cisco Identity Services Engine (ISE) version 3.4, immediate patching is recommended to prevent attackers from triggering a DoS via crafted RADIUS requests, causing system reboots. As a temporary workaround, consider restricting access to the RADIUS message processing feature until a patch is available. Avoid using the vulnerable RADIUS implementation in the affected API endpoint until the issue is resolved.

Fix

DoS

LPE

Out of bounds Read

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-05639
CVE-2025-20152

Affected Products

Cisco Identity Services Engine