Cisco Identity Services Engine RADIUS Suppression Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 8.6 Security Advisory

TL;DR 📌

A vulnerability in Cisco Identity Services Engine (ISE) could allow unauthenticated attackers to cause a denial of service (DoS) by exploiting a logic error in RADIUS request processing. Affected versions include 3.4.0 and its patches. Cisco recommends upgrading to fixed software or disabling a specific setting as a workaround.

What happened 🕵️‍♂️

A vulnerability has been identified in the RADIUS setting “Reject RADIUS requests from clients with repeated failures” in Cisco Identity Services Engine (ISE). This flaw allows an unauthenticated remote attacker to send crafted RADIUS access requests that can cause Cisco ISE to restart unexpectedly, leading to a denial of service (DoS) condition.

Affected products 🖥️

The following Cisco ISE releases are affected:

  • 3.4.0
  • 3.4 Patch 1
  • 3.4 Patch 2
  • 3.4 Patch 3

The default configuration has the vulnerable setting enabled. Cisco ISE Passive Identity Connector (ISE-PIC) is confirmed not to be affected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
3.3 and earlier Not vulnerable
3.4 3.4 Patch 4
3.5 Not vulnerable
1.0 Initial public release.
Cisco ISE 3.4 Patch 4 3.4

Workarounds 🧯

Administrators can disable the vulnerable setting by:

  1. Navigating to Administration > System > Settings > Protocols > RADIUS in the Cisco ISE web UI.
  2. Unchecking the “Reject RADIUS requests from clients with repeated failures” checkbox.

This setting is enabled by default, so disabling it will mitigate the vulnerability until a software upgrade is performed. However, it is advised to re-enable the setting after upgrading.

Risk in context 🎯

With a CVSS score of 8.6, this vulnerability is rated as High. The exposure is significant as it allows unauthenticated access to cause a DoS. The risk is particularly notable for internet-facing deployments, where attackers can exploit this flaw without needing credentials.

Fast facts ⚡

  • CVSS Score: 8.6 (High)
  • Vulnerable Setting: Reject RADIUS requests from clients with repeated failures
  • Affected Versions: Cisco ISE 3.4.0 and patches
  • Mitigation: Disable the vulnerable setting or upgrade to fixed software

For leadership 🧭

Executive summary. Cisco ISE 3.4 deployments running the default RADIUS configuration can be forced offline by anyone able to send RADIUS traffic to them, without any credentials required. Because ISE typically underpins network access control, an outage here can block legitimate users and devices from authenticating, so this warrants attention before the next change window rather than waiting for routine patch cycles.

Why it matters:

  • The flaw sits in the default-enabled ‘Reject RADIUS requests from clients with repeated failures’ setting, so most 3.4.0 through 3.4 Patch 3 deployments are exposed out of the box.
  • No authentication is needed to trigger the crash; a crafted RADIUS access request is enough to force an unexpected restart of the ISE process.
  • ISE is the RADIUS/authentication chokepoint for network access in many environments, so a forced restart can disrupt wired, wireless, or VPN authentication until the service recovers.
  • ISE-PIC is confirmed unaffected, so the exposure is specific to full ISE deployments running the vulnerable 3.4 releases.

Now / Next / Later:

  • Now: Disable the ‘Reject RADIUS requests from clients with repeated failures’ checkbox under Administration > System > Settings > Protocols > RADIUS on any Cisco ISE 3.4.0–3.4 Patch 3 deployment.
  • Next: Schedule an upgrade to 3.4 Patch 4 (or later) during the next maintenance window, since this removes the underlying logic error rather than just masking it.
  • Later: After upgrading, re-enable the RADIUS repeated-failures setting and add Cisco ISE patch levels to routine vulnerability tracking so future advisories affecting this authentication chokepoint are actioned promptly.