QID 317352

Date Published: 2023-10-03

QID 317352: Cisco Identity Services Engine (ISE) RADIUS Service Denial of Service (DoS) Vulnerability (cisco-sa-ise-radius-dos-W7cNn7gt)

A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets.

Note: To recover the ability to process RADIUS packets, a manual restart of the affected Policy Service Node (PSN) may be required. For more information, see the Details section of this advisory. Affected version:
From 3.1 Prior to 3.1P7
From 3.2 Prior to 3.2P3
QID Detection Logic (Authenticated):
The check matches the Cisco ISE version and ise_patch retrieved via Unix Auth using "show version" command.

Note: This QID does not check if TACAS is used in Cisco ISE. Hence QID kept as Practice.

A successful exploit could allow the attacker to cause the RADIUS process to unexpectedly restart, resulting in authentication or authorization timeouts and denying legitimate users access to the network or service.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to cisco-sa-ise-radius-dos-W7cNn7gt for more information.

    CVEs related to QID 317352

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-ise-radius-dos-W7cNn7gt URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-radius-dos-W7cNn7gt