CVE-2022-20756
Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by attempting to authenticate to a network or a service where the access server is using Cisco ISE as the RADIUS server. A successful exploit could allow the attacker to cause Cisco ISE to stop processing RADIUS requests, causing authentication/authorization timeouts, which would then result in legitimate requests being denied access. Note: To recover the ability to process RADIUS packets, a manual restart of the affected Policy Service Node (PSN) is required. See the Details section for more information.
Una vulnerabilidad en la función RADIUS de Cisco Identity Services Engine (ISE) podría permitir a un atacante remoto no autenticado causar que el sistema afectado deje de procesar paquetes RADIUS. Esta vulnerabilidad es debido al manejo inapropiado de determinadas peticiones RADIUS. Un atacante podría explotar esta vulnerabilidad intentando autenticarse en una red o un servicio en el que el servidor de acceso esté utilizando Cisco ISE como servidor RADIUS. Una explotación con éxito podría permitir al atacante hacer que Cisco ISE dejara de procesar las peticiones RADIUS, causando tiempos de espera de autenticación/autorización, lo que resulta en que sea denegado el acceso a peticiones legítimas. Nota: Para recuperar la capacidad de procesar paquetes RADIUS, es necesario reiniciar manualmente el Policy Service Node (PSN) afectado. Consulte la sección Detalles para más información
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2021-11-02 CVE Reserved
- 2022-04-06 CVE Published
- 2024-11-06 CVE Updated
- 2024-11-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-399: Resource Management Errors
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-dos-JLh9TxBp | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.2.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.2.0" | patch17 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.4.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.4.0" | patch12 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.4.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.4.0" | patch13 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.4.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.4.0" | patch14 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.6.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.6.0" | patch10 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.6.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.6.0" | patch5 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.6.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.6.0" | patch6 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.6.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.6.0" | patch7 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.6.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.6.0" | patch8 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.6.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.6.0" | patch9 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.7.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.7.0" | patch2 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.7.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.7.0" | patch3 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.7.0 Search vendor "Cisco" for product "Identity Services Engine" and version "2.7.0" | patch4 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 2.7.0.356 Search vendor "Cisco" for product "Identity Services Engine" and version "2.7.0.356" | patch1 |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 3.0.0 Search vendor "Cisco" for product "Identity Services Engine" and version "3.0.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Identity Services Engine Search vendor "Cisco" for product "Identity Services Engine" | 3.1 Search vendor "Cisco" for product "Identity Services Engine" and version "3.1" | - |
Affected
|