Description
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the node comes back up on its own.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the RADIUS handling within Cisco Identity Services Engine allows an unauthenticated attacker to send a crafted request that may crash the ISE node, making the device unavailable. The vulnerability stems from improper input validation identified as CWE‑119, leading to denial of service. When exploited, endpoints that have not yet authenticated will be unable to obtain network access until the affected node recovers on its own, thereby disrupting network connectivity for connected users.

Affected Systems

The affected product is Cisco Identity Services Engine Software. No specific version information is provided in the advisory; any deployment that includes the vulnerable RADIUS component is potentially impacted.

Risk and Exploitability

The CVSS score of 8.6 signals a high severity, and while the EPSS score of less than 1% indicates a low expected likelihood of exploitation, the risk remains because the vulnerability is remote and requires no privileges. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. An attacker can exploit it by sending malicious RADIUS packets over the network to the ISE node; successful exploitation results in a denial of service that can affect all endpoints relying on that node.

Generated by OpenCVE AI on September 18, 2026 at 01:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade to a version that fixes the RADIUS DoS flaw
  • Restrict RADIUS traffic to only trusted sources by configuring firewall rules or access‑control lists so that unauthorized users cannot reach the ISE node
  • Continuously monitor ISE logs and performance metrics for unusual RADIUS request patterns or crashes, and maintain procedures to restart or isolate the node during a DoS incident

Generated by OpenCVE AI on September 18, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco identity Services Engine Software
Vendors & Products Cisco
Cisco identity Services Engine Software

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the&nbsp;node comes back up on its own.
Title Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
Weaknesses CWE-119
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Cisco Identity Services Engine Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-17T16:01:38.332Z

Reserved: 2025-10-08T11:59:15.414Z

Link: CVE-2026-20352

cve-icon Vulnrichment

Updated: 2026-09-17T16:01:24.163Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:12.517

Modified: 2026-09-18T13:28:28.567

Link: CVE-2026-20352

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:31:28Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer