
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20343 is a denial-of-service vulnerability in the RADIUS suppression feature of Cisco Identity Services Engine (ISE) that allows an unauthenticated, remote attacker to cause the system to restart unexpectedly. The vulnerability affects Cisco ISE releases 3.4.0, 3.4 Patch 1, 3.4 Patch 2, and 3.4 Patch 3 — specifically when the "Reject RADIUS requests from clients with repeated failures" setting is enabled (which is the default configuration). It was first published on November 5, 2025, and a patch was released on November 19, 2025. The CVSS v3.1 base score is 8.6 (High) (Cisco Advisory).
The root cause is a logic error (CWE-697: Incorrect Comparison) in how Cisco ISE processes RADIUS access requests for MAC addresses that are already marked as rejected endpoints. When the "Reject RADIUS requests from clients with repeated failures" feature is active, a flaw in the comparison logic can be triggered by sending a specific sequence of multiple crafted RADIUS access request messages, causing the ISE process to crash and restart. No authentication, privileges, or user interaction are required, and the attack is network-accessible with low complexity. A public proof-of-concept exploit has been published on GitHub (Cisco Advisory, Feedly).
Successful exploitation causes Cisco ISE to restart unexpectedly, resulting in a denial-of-service (DoS) condition that disrupts network authentication and access control services. Since Cisco ISE is commonly used as a central policy enforcement point for network access control (NAC), 802.1X authentication, and RADIUS-based authorization, an outage can prevent users and devices from authenticating to the network, potentially causing widespread connectivity disruption. There is no confidentiality or integrity impact — the vulnerability is limited to availability (Cisco Advisory).
A public proof-of-concept exploit is available on GitHub (https://github.com/fevar54/Blackash-CVE-2025-20343), added to Feedly's tracking on March 2, 2026. The Cisco PSIRT stated at the time of initial disclosure that it was not aware of any public announcements or malicious use of the vulnerability; however, the PoC availability increases exploitation risk. The EPSS score is approximately 0.00138 (low probability of exploitation in the near term). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of available data (Cisco Advisory, Feedly).
/opt/CSCOcpm/logs/ise-psc.log or equivalent ISE log files.Cisco has released ISE 3.4 Patch 4 as the fixed release for the 3.4 branch; ISE 3.3 and earlier and ISE 3.5 are not affected. As an immediate workaround, administrators can disable the vulnerable setting by navigating to Administration > System > Settings > Protocols > RADIUS, then unchecking the "Reject RADIUS requests from clients with repeated failures" checkbox under the "Suppress Repeated Failed Clients and repeated accounting" section. Cisco recommends re-enabling this setting after upgrading to the fixed release. Additionally, implementing network-level access controls to restrict RADIUS traffic (UDP/1812) to only trusted network access devices can reduce exposure (Cisco Advisory).
The vulnerability received coverage from security news outlets including Heise and BleepingComputer in the context of broader Cisco vulnerability disclosures in November 2025. Security community members shared the advisory on Mastodon and Bluesky, and the vulnerability was included in weekly threat digests by outlets such as The Hacker News and IT Briefcase. SecPod published a dedicated technical blog post titled "Reject, Repeat, Restart: RADIUS Bug Triggers Cisco ISE DoS," and ZeroPath published a summary analysis. The Cisco PSIRT noted the vulnerability was discovered internally through a TAC support case, not by an external researcher (Cisco Advisory, SecPod Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."