{"id":8269,"date":"2025-11-07T10:05:20","date_gmt":"2025-11-07T10:05:20","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/07\/cisco-identity-services-engine-vulnerability-allows-attackers-to-restart-ise-unexpectedly\/"},"modified":"2025-11-07T10:05:20","modified_gmt":"2025-11-07T10:05:20","slug":"cisco-identity-services-engine-vulnerability-allows-attackers-to-restart-ise-unexpectedly","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/07\/cisco-identity-services-engine-vulnerability-allows-attackers-to-restart-ise-unexpectedly\/","title":{"rendered":"Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE Unexpectedly"},"content":{"rendered":"<p>    Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE Unexpectedly<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical vulnerability in Cisco Identity Services Engine (ISE) could allow remote attackers to crash the system through a crafted sequence of RADIUS requests.<\/p>\n<p>The flaw <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2024-20399\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2024-20399<\/a>, lies in how ISE handles repeated authentication failures from rejected endpoints, creating a <a href=\"https:\/\/cybersecuritynews.com\/fbi-warning-tdos\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service<\/a> condition that forces unexpected system restarts.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/openvpn-vulnerability-exposes-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">vulnerability<\/a> stems from a logic error in the RADIUS configuration that rejects client requests after repeated failures.<\/p>\n<p>Attackers can exploit this by sending specially crafted RADIUS access request messages targeting MAC addresses already flagged as rejected endpoints.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-cisco-identity-services-engine-vulnerability\"><strong>Cisco Identity Services Engine Vulnerability<\/strong><\/h2>\n<p>When ISE processes these malicious requests, the system crashes and restarts unexpectedly, disrupting authentication services across the network.<\/p>\n<p>This type of attack requires no authentication credentials, making it particularly dangerous for organizations relying on ISE for network access control and endpoint management.<\/p>\n<p>Cisco ISE versions 3.4.0 through 3.4 Patch 3 are vulnerable by default because the \u201cReject <a href=\"https:\/\/cybersecuritynews.com\/cisco-identity-services-radius-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">RADIUS requests<\/a> from clients with repeated failures\u201d setting is enabled by default in these releases.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE ID<\/th>\n<th>Product<\/th>\n<th>Affected Versions<\/th>\n<th>CVSS v3.1 Score<\/th>\n<th><strong>Vulnerability Type<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2024-20399<\/td>\n<td>Cisco ISE<\/td>\n<td>3.4.0, 3.4 P1, 3.4 P2, 3.4 P3<\/td>\n<td>7.5<\/td>\n<td>Denial of Service (DoS)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>ISE serves as a central point for network access control, device authentication, and compliance policy enforcement.<\/p>\n<p>When ISE restarts unexpectedly, organizations lose visibility into network activity and may experience authentication failures for legitimate users and devices.<\/p>\n<p>This cascading effect can disrupt business operations across the entire network infrastructure. Cisco has<a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-ise-radsupress-dos-8YF3JThh\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> released<\/a> multiple options to address this threat.<\/p>\n<p>Organizations can immediately turn off the vulnerable RADIUS setting in the administration console. However, Cisco recommends re-enabling it once systems are patched.<\/p>\n<p>ISE version 3.4 systems should be upgraded to <a href=\"https:\/\/cybersecuritynews.com\/wsus-rce-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Patch <\/a>4 or later. Notably, earlier versions (3.3 and below) and newer releases (3.5+) are not affected by this issue.<\/p>\n<p>Administrators should check their ISE configuration at Administration &gt; System &gt; Settings &gt; Protocols &gt; RADIUS to verify their current status.<\/p>\n<p>The vulnerability only affects systems with the repeated failures rejection setting enabled, so disabling it provides temporary protection while upgrades are planned.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisco-identity-services-engine-ddos-vulnerability\/\">Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE Unexpectedly<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisco-identity-services-engine-ddos-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE Unexpectedly A critical vulnerability in Cisco Identity Services Engine (ISE) could allow remote attackers to crash the system through a crafted sequence of RADIUS requests. The flaw CVE-2024-20399, lies in how ISE handles repeated authentication failures from rejected endpoints, creating a denial-of-service condition that forces [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2015,63,464,2016,648],"tags":[130],"class_list":["post-8269","post","type-post","status-publish","format-standard","hentry","category-cve-vulnerabilities","category-cyber-security-news","category-cybersecurity","category-cybersecurity-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8269"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8269"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8269\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8269"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8269"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8269"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}