Cisco Identity Services Engine RADIUS Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) versions 3.4 and 3.3 and earlier. This vulnerability allows an unauthenticated, remote attacker to cause the affected device to reload. The issue arises from improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a specific authentication request to a network access device that uses Cisco ISE for authentication, authorization, and accounting services.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the affected Cisco ISE device to reload.

Remediation

Cisco has released free software updates that address this vulnerability. Customers with service contracts should obtain these security fixes through their usual update channels. For instructions on upgrading a device, see the Upgrade Guides on the Cisco Identity Service Engine support page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.