ZeroHour

CVE-2026-20352

large

Unauthenticated RADIUS DoS in Cisco Identity Services Engine (ISE)

CVSS 3.1
8.6 high
EPSS
Published
()
Modified
AI analysis

Cisco Identity Services Engine (ISE) contains a denial-of-service vulnerability in its RADIUS feature caused by improper handling of certain RADIUS requests (CWE-119). An unauthenticated, remote attacker can trigger it by sending a crafted RADIUS request directly to an affected ISE node, with no user interaction or credentials required. A successful exploit makes the ISE node unavailable; in single-node deployments, endpoints that have not already authenticated cannot access the network until the node recovers on its own, and even in larger clusters RADIUS-based network access can be disrupted. All organizations running Cisco ISE with the RADIUS/network-access-control feature enabled are potentially affected, particularly single-node deployments. As of now there is no evidence of exploitation in the wild, no CISA KEV listing, and no public proof-of-concept.

What to do: Check the Cisco PSIRT advisory for this CVE and upgrade ISE nodes to the fixed releases it specifies. As an interim mitigation, restrict which devices can send RADIUS traffic (UDP 1812/1813) to the ISE policy service nodes using ACLs or firewall rules so only trusted network access devices can reach the service. Operators of single-node deployments should prioritize patching and ensure ISE is monitored so an unavailable node is detected and allowed to recover.

Affected
Cisco Identity Services Engine (ISE) with RADIUS feature enabled
Estimated exposure
largelikely tens of thousands of enterprise deployments worldwide (ISE is typically deployed as 2+ nodes per organization), with essentially none directly… — Cisco ISE is one of the most widely deployed enterprise NAC platforms, but it is an internal network-access-control product whose RADIUS service is normally reachable only from network access devices, so the estimate is based on Cisco's…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the node comes back up on its own.

Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.