
CVE-2025-20343
🚨 High-severity denial-of-service (DoS) flaw in Cisco Identity Services Engine (ISE)!
💥 An unauthenticated remote attacker can crash the device with crafted RADIUS packets.
📅 Disclosed: November 5, 2025
✅ No known exploitation in the wild (yet!)
🔄 A logic error in the "Reject RADIUS requests from clients with repeated failures" setting.
🕵️♂️ Attacker sends crafted RADIUS Access-Requests targeting a rejected MAC address.
💣 Triggers unexpected restart → DoS condition
🌍 Requires network access to RADIUS port — no auth needed!
CWE-697: Incorrect Comparison Logic
🔴 CVSS v3.1: 8.6 (High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Product: Cisco Identity Services Engine (ISE)
Vulnerable Versions:
Only if using RADIUS (802.1X, VPN, etc.)
HA clusters may reduce downtime via failover
| Status | Details |
|---|---|
| 🚫 In the Wild | None reported |
| ⚙️ Difficulty | Low – Just send repeated RADIUS packets |
| 🎯 Likely Target | Enterprises using ISE for NAC, Wi-Fi, or VPN auth |
🔧 Fix It
🔥 Workarounds
🛡️ Best Practices
⚡ Action Item: If you run Cisco ISE 3.4, patch now! This is a low-effort, high-impact attack waiting to happen. 🚀
Stay secure! 🔐
| Metric | Value | Meaning |
|---|
| 🔗 Attack Vector | Network | Remotely exploitable |
| ⚡ Complexity | Low | No special skills/tools |
| 🛡️ Privileges | None | Unauthenticated |
| 👤 User Interaction | None | Fully automated |
| 🌍 Scope | Changed | Impacts beyond ISE |
| 🔒 Confidentiality | None | No data leak |
| ✅ Integrity | None | No tampering |
| ⛔ Availability | High | Full service outage |