QID 317260
Date Published: 2022-11-09
QID 317260: Cisco Identity Services Engine (ISE) Software Resource Exhaustion Vulnerability (cisco-sa-ise-sec-atk-dos-zw5RCUYp)
A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device.
Affected Products
Cisco ISE following vulnerable versions:
Prior to 2.7 patch 8
From 3.0 Prior to 3.0 patch 6
From 3.1 Prior to 3.1 patch 4
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.
Note: This QID does not checks for the device configuration hence keeping it as practice.
A successful and sustained exploit of this vulnerability could allow the attacker to cause reduced performance of the affected device, resulting in significant delays to RADIUS authentications.
Customers are advised to refer to cisco-sa-ise-sec-atk-dos-zw5RCUYp for more information.
- cisco-sa-ise-sec-atk-dos-zw5RCUYp -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sec-atk-dos-zw5RCUYp
CVEs related to QID 317260
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-ise-sec-atk-dos-zw5RCUYp |
|