CVE-2025-20343
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-05

Last updated on: 2025-11-19

Assigner: Cisco Systems, Inc.

Description
A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a MAC address that is already a rejected endpoint. An attacker could exploit this vulnerability by sending a specific sequence of multiple crafted RADIUS access request messages to Cisco ISE. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when Cisco ISE restarts.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-05
Last Modified
2025-11-19
Generated
2026-05-07
AI Q&A
2025-11-05
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
cisco identity_services_engine 3.4.0
cisco identity_services_engine 3.4.0
cisco identity_services_engine 3.4.0
cisco identity_services_engine 3.4.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-697 The product compares two entities in a security-relevant context, but the comparison is incorrect.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the Cisco Identity Services Engine (ISE) RADIUS setting that rejects requests from clients with repeated failures. Due to a logic error, when processing RADIUS access requests for MAC addresses already marked as rejected, an unauthenticated remote attacker can send a specific sequence of crafted RADIUS access request messages that causes Cisco ISE to restart unexpectedly.


How can this vulnerability impact me? :

Exploiting this vulnerability can cause a denial of service (DoS) condition by forcing Cisco ISE to restart unexpectedly. This can disrupt network access control services and potentially impact network availability and security monitoring.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart