Executive brief
Cisco Identity Services Engine (ISE) is an authentication and access control platform used to manage network access for corporate devices and users. A vulnerability in its RADIUS authentication feature allows an unauthenticated attacker to remotely crash ISE nodes by sending malformed RADIUS requests, causing network authentication services to go offline. In single-node deployments, this prevents any new devices from connecting to the network until the service restarts.
Technical details
This is a buffer overflow vulnerability (CWE-119) in the RADIUS request handler of Cisco ISE Policy Service Nodes. An unauthenticated, remote attacker can send a crafted RADIUS packet to trigger the overflow, causing denial of service. The vulnerability requires no authentication or user interaction and affects RADIUS-enabled nodes on the network layer (AV:N). The ISE node becomes unavailable until manual recovery or automatic restart. Patches are available for ISE versions 3.2 through 3.5 (3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4); versions 3.1 and earlier are not vulnerable.
Affected products
- Cisco Identity Services Engine 3.2 through 3.5 (before patch versions)
Timeline
- 2026-09-16: disclosed