Cisco Identity Services Engine RADIUS Denial of Service Vulnerability
Cisco patched a RADIUS flaw in Identity Services Engine letting unauthenticated remote attackers trigger denial of service on ISE nodes.
A vulnerability in the RADIUS feature of Cisco Identity Services Engine allows an unauthenticated remote attacker to cause a denial of service by sending crafted RADIUS requests directly to an affected device. The flaw stems from improper handling of certain RADIUS requests and can render ISE nodes unavailable. In single-node deployments, endpoints that have not yet authenticated would be unable to access the network until the node recovers. Cisco has released software updates addressing the issue.
35