Impact
A flaw in the RADIUS handling within Cisco Identity Services Engine allows an unauthenticated attacker to send a crafted request that may crash the ISE node, making the device unavailable. The vulnerability stems from improper input validation identified as CWE‑119, leading to denial of service. When exploited, endpoints that have not yet authenticated will be unable to obtain network access until the affected node recovers on its own, thereby disrupting network connectivity for connected users.
Affected Systems
The affected product is Cisco Identity Services Engine Software. No specific version information is provided in the advisory; any deployment that includes the vulnerable RADIUS component is potentially impacted.
Risk and Exploitability
The CVSS score of 8.6 signals a high severity, and while the EPSS score of less than 1% indicates a low expected likelihood of exploitation, the risk remains because the vulnerability is remote and requires no privileges. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. An attacker can exploit it by sending malicious RADIUS packets over the network to the ISE node; successful exploitation results in a denial of service that can affect all endpoints relying on that node.
OpenCVE Enrichment