CVE-2026-20352
largeUnauthenticated RADIUS DoS in Cisco Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE) contains a denial-of-service vulnerability in its RADIUS feature caused by improper handling of certain RADIUS requests (CWE-119). An unauthenticated, remote attacker can trigger it by sending a crafted RADIUS request directly to an affected ISE node, with no user interaction or credentials required. A successful exploit makes the ISE node unavailable; in single-node deployments, endpoints that have not already authenticated cannot access the network until the node recovers on its own, and even in larger clusters RADIUS-based network access can be disrupted. All organizations running Cisco ISE with the RADIUS/network-access-control feature enabled are potentially affected, particularly single-node deployments. As of now there is no evidence of exploitation in the wild, no CISA KEV listing, and no public proof-of-concept.
What to do: Check the Cisco PSIRT advisory for this CVE and upgrade ISE nodes to the fixed releases it specifies. As an interim mitigation, restrict which devices can send RADIUS traffic (UDP 1812/1813) to the ISE policy service nodes using ACLs or firewall rules so only trusted network access devices can reach the service. Operators of single-node deployments should prioritize patching and ensure ISE is monitored so an unavailable node is detected and allowed to recover.
| Cisco Identity Services Engine (ISE) with RADIUS feature enabled | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the node comes back up on its own.
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.