QID 317139

Date Published: 2022-03-03

QID 317139: Cisco Identity Services Engine (ISE) RADIUS Service Denial of Service (DoS) Vulnerability (cisco-sa-ise-dos-JLh9TxBp)

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets.

Affected version:
From 2.4 Prior to 2.6P11
From 2.7 Prior to 2.7P6
From 3.0 Prior to 3.0P5
From 3.1 Prior to 3.1P1
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.

Note: This QID does not check if TACAS is used in Cisco ISE. Hence QID kept as Practice.

A successful exploit could allow the attacker to cause Cisco ISE to stop processing RADIUS requests, causing authentication/authorization timeouts, which would then result in legitimate requests being denied access.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ise-dos-JLh9TxBp for more information.

    CVEs related to QID 317139

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ise-dos-JLh9TxBp URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-dos-JLh9TxBp