Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
TL;DR 📌
A vulnerability in the Cisco Identity Services Engine (ISE) related to RADIUS message processing could allow an unauthenticated attacker to trigger a denial of service (DoS) condition. Cisco has released software updates to address this issue, but there are no workarounds available.
What happened 🕵️♂️
Cisco has identified a vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE). This flaw allows an unauthenticated, remote attacker to send specific authentication requests that can cause the Cisco ISE to reload, leading to a denial of service (DoS) condition. The vulnerability is attributed to improper handling of certain RADIUS requests.
Affected products 🖥️
The vulnerability affects Cisco ISE when it is configured with RADIUS authentication services. Notably, RADIUS services are enabled by default. If Cisco ISE is used solely for TACACS+, it is not affected by this vulnerability.
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 3.3 and earlier | Not vulnerable | |
| ISE / ISE-PIC 3.4 | 3.4P1 | |
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to mitigate this vulnerability.
Risk in context 🎯
With a CVSS score of 8.6, this vulnerability is classified as HIGH severity. Organizations using Cisco ISE with RADIUS authentication should prioritize applying the fixed software updates to prevent potential exploitation that could lead to service disruptions.
Fast facts ⚡
- Vulnerability: Cisco Identity Services Engine RADIUS Denial of Service
- CVSS Score: 8.6 (HIGH)
- Exploitation: Possible via unauthenticated remote access
- Fixed Software: Cisco ISE 3.4P1
- Workarounds: None available
For leadership 🧭
Executive summary. Any Cisco ISE deployment using RADIUS authentication, the default configuration, can be crashed remotely by an unauthenticated party sending malformed requests, disrupting network access control until it restarts. There is no workaround, so this needs patching on the next available change window rather than being left for routine maintenance.
Why it matters:
- RADIUS authentication is enabled on Cisco ISE by default, so most deployments are exposed unless they run TACACS+ only.
- No authentication is required to trigger the crash, meaning anyone who can reach the RADIUS service can force a reload.
- A reload of ISE interrupts network access control and authentication decisions across every device and user relying on it.
- There is no workaround, so the only mitigation is upgrading to a fixed release.
Now / Next / Later:
- Now: Identify every Cisco ISE / ISE-PIC deployment and confirm whether RADIUS authentication is enabled; treat any that are as exposed.
- Next: Upgrade ISE 3.4 deployments to 3.4P1 (or later) in the next change window; ISE / ISE-PIC 3.3 and earlier are not affected by this issue.
- Later: Restrict network reachability to RADIUS services on ISE to only the switches, wireless controllers and VPN concentrators that need it, so future protocol-handling flaws have a smaller exposed surface.