CVE-2025-20343
Cisco ISE vulnerability analysis and mitigation

Overview

CVE-2025-20343 is a denial-of-service vulnerability in the RADIUS suppression feature of Cisco Identity Services Engine (ISE) that allows an unauthenticated, remote attacker to cause the system to restart unexpectedly. The vulnerability affects Cisco ISE releases 3.4.0, 3.4 Patch 1, 3.4 Patch 2, and 3.4 Patch 3 — specifically when the "Reject RADIUS requests from clients with repeated failures" setting is enabled (which is the default configuration). It was first published on November 5, 2025, and a patch was released on November 19, 2025. The CVSS v3.1 base score is 8.6 (High) (Cisco Advisory).

Technical details

The root cause is a logic error (CWE-697: Incorrect Comparison) in how Cisco ISE processes RADIUS access requests for MAC addresses that are already marked as rejected endpoints. When the "Reject RADIUS requests from clients with repeated failures" feature is active, a flaw in the comparison logic can be triggered by sending a specific sequence of multiple crafted RADIUS access request messages, causing the ISE process to crash and restart. No authentication, privileges, or user interaction are required, and the attack is network-accessible with low complexity. A public proof-of-concept exploit has been published on GitHub (Cisco Advisory, Feedly).

Impact

Successful exploitation causes Cisco ISE to restart unexpectedly, resulting in a denial-of-service (DoS) condition that disrupts network authentication and access control services. Since Cisco ISE is commonly used as a central policy enforcement point for network access control (NAC), 802.1X authentication, and RADIUS-based authorization, an outage can prevent users and devices from authenticating to the network, potentially causing widespread connectivity disruption. There is no confidentiality or integrity impact — the vulnerability is limited to availability (Cisco Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Cisco ISE instances running version 3.4.0, 3.4 Patch 1, 3.4 Patch 2, or 3.4 Patch 3 using network scanning tools or Shodan. Confirm the RADIUS port (UDP 1812) is reachable.
  2. Verify feature is enabled: The "Reject RADIUS requests from clients with repeated failures" setting is enabled by default in ISE 3.4.x, so most deployments will be vulnerable without additional verification.
  3. Identify a rejected MAC address: Determine or guess a MAC address that has already been rejected by the ISE endpoint database (e.g., through prior failed authentication attempts or by sending initial failed RADIUS requests to populate the rejected endpoint list).
  4. Craft malicious RADIUS sequence: Construct a specific sequence of multiple RADIUS Access-Request messages targeting the rejected MAC address, exploiting the logic error in the comparison routine that handles already-rejected endpoints.
  5. Trigger DoS: Send the crafted RADIUS packet sequence to the ISE RADIUS listener (UDP port 1812). The logic error causes ISE to crash and restart, resulting in a denial-of-service condition affecting all network authentication services (Cisco Advisory, Feedly).

Indicators of compromise

  • Network: Unusual volume of RADIUS Access-Request packets (UDP/1812) from a single or rotating source IP targeting the same MAC address; RADIUS traffic patterns inconsistent with normal authentication flows.
  • Logs: Cisco ISE application logs showing repeated RADIUS access requests for a MAC address already in the rejected endpoint list, followed by unexpected process termination or restart events in /opt/CSCOcpm/logs/ise-psc.log or equivalent ISE log files.
  • Process/System: Unexpected ISE service restarts or crashes; ISE admin UI becoming temporarily unavailable; alerts from ISE health monitoring indicating unplanned node restarts.
  • RADIUS Accounting: Gaps in RADIUS accounting records corresponding to ISE restart windows, indicating authentication service interruption (Cisco Advisory).

Mitigation and workarounds

Cisco has released ISE 3.4 Patch 4 as the fixed release for the 3.4 branch; ISE 3.3 and earlier and ISE 3.5 are not affected. As an immediate workaround, administrators can disable the vulnerable setting by navigating to Administration > System > Settings > Protocols > RADIUS, then unchecking the "Reject RADIUS requests from clients with repeated failures" checkbox under the "Suppress Repeated Failed Clients and repeated accounting" section. Cisco recommends re-enabling this setting after upgrading to the fixed release. Additionally, implementing network-level access controls to restrict RADIUS traffic (UDP/1812) to only trusted network access devices can reduce exposure (Cisco Advisory).

Community reactions

The vulnerability received coverage from security news outlets including Heise and BleepingComputer in the context of broader Cisco vulnerability disclosures in November 2025. Security community members shared the advisory on Mastodon and Bluesky, and the vulnerability was included in weekly threat digests by outlets such as The Hacker News and IT Briefcase. SecPod published a dedicated technical blog post titled "Reject, Repeat, Restart: RADIUS Bug Triggers Cisco ISE DoS," and ZeroPath published a summary analysis. The Cisco PSIRT noted the vulnerability was discovered internally through a TAC support case, not by an external researcher (Cisco Advisory, SecPod Blog).

Additional resources


SourceThis report was generated using AI

Related Cisco ISE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20181CRITICAL9.1
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20190HIGH7.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJun 17, 2026
CVE-2026-20146MEDIUM5.5
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoJul 15, 2026
CVE-2026-20195MEDIUM5.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026
CVE-2026-20193MEDIUM4.3
  • Cisco ISE logoCisco ISE
  • cpe:2.3:a:cisco:identity_services_engine
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management