Cisco has announced a critical vulnerability in its Identity Services Engine (ISE) that could allow attackers to cause system reboots via specially crafted RADIUS requests. While no exploits have been observed in the wild, immediate patching and network monitoring are recommended to prevent service disruptions. #CVE-2025-20152 #CiscoISE #RadiusVulnerability
Keypoints
- The vulnerability affects Cisco ISE 3.4 and is categorized as high severity with a CVSS score of 8.6.
- It exploits improper handling of RADIUS requests, leading to a potential denial of service through system reloads.
- The flaw exists in the RADIUS message processing component and is related to CWE-125 (Out-of-bounds Read).
- Cisco has released ISE 3.4P1 as a patch, and organizations are urged to update immediately as no workaround is available.
- Applying network segmentation, monitoring logs, and restricting RADIUS access can help mitigate risks until patches are deployed.
Read More: https://cybersecuritynews.com/cisco-identity-services-radius-vulnerability/