Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Blackash-CVE-2025-20343 — CVE-2025-20343 | Kitploit
Tools/GitHubGitHub/fevar54/blackash-cve-2025-20343
Authentication & AuthorizationVulnerability AnalysisExploitationInformation GatheringNetwork Security
GitHubfevar54/blackash-cve-2025-20343

Blackash-CVE-2025-20343

CVE-2025-20343

View Repository
9 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🔒 CVE-2025-20343: Cisco ISE RADIUS Suppression DoS Vulnerability 🌐


⚠️ Overview

🚨 High-severity denial-of-service (DoS) flaw in Cisco Identity Services Engine (ISE)!
💥 An unauthenticated remote attacker can crash the device with crafted RADIUS packets.
📅 Disclosed: November 5, 2025
✅ No known exploitation in the wild (yet!)


🛠️ How It Works

🔄 A logic error in the "Reject RADIUS requests from clients with repeated failures" setting.
🕵️‍♂️ Attacker sends crafted RADIUS Access-Requests targeting a rejected MAC address.
💣 Triggers unexpected restart → DoS condition
🌍 Requires network access to RADIUS port — no auth needed!

CWE-697: Incorrect Comparison Logic


📊 Severity Score

🔴 CVSS v3.1: 8.6 (High)

root@kitploit:~
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

🖥️ Affected Systems

Product: Cisco Identity Services Engine (ISE)
Vulnerable Versions:

  • 3.4.0
  • 3.4 Patch 1
  • 3.4 Patch 2
  • 3.4 Patch 3

Only if using RADIUS (802.1X, VPN, etc.)
HA clusters may reduce downtime via failover


🛡️ Exploitation Status

StatusDetails
🚫 In the WildNone reported
⚙️ DifficultyLow – Just send repeated RADIUS packets
🎯 Likely TargetEnterprises using ISE for NAC, Wi-Fi, or VPN auth

🛑 Mitigation & Fixes

🔧 Fix It

  • Upgrade to patched ISE version (check Cisco advisory)
  • 📌 Apply ASAP — easy to exploit!

🔥 Workarounds

  • Disable “Reject repeated failures” (⚠️ reduces brute-force protection)
  • Filter RADIUS traffic with ACLs/firewalls
  • Deploy HA with tested failover

🛡️ Best Practices

  • 🧪 Test patches in lab first
  • 📡 Monitor for: restarts, RADIUS spikes, auth failures
  • ⏰ Patch during maintenance windows

📚 References

  • 🔗 Cisco Official Advisory
  • 📰 RedPacket Security
  • 💻 BleepingComputer
  • 🇩🇪 Heise Online

⚡ Action Item: If you run Cisco ISE 3.4, patch now! This is a low-effort, high-impact attack waiting to happen. 🚀

Stay secure! 🔐

Download Tool
MetricValueMeaning
🔗 Attack VectorNetworkRemotely exploitable
⚡ ComplexityLowNo special skills/tools
🛡️ PrivilegesNoneUnauthenticated
👤 User InteractionNoneFully automated
🌍 ScopeChangedImpacts beyond ISE
🔒 ConfidentialityNoneNo data leak
✅ IntegrityNoneNo tampering
⛔ AvailabilityHighFull service outage