← Back

CVE-2022-20756

nvd nist
Published: Apr 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by attempting to authenticate to a network or a service where the access server is using Cisco ISE as the RADIUS server. A successful exploit could allow the attacker to cause Cisco ISE to stop processing RADIUS requests, causing authentication/authorization timeouts, which would then result in legitimate requests being denied access. Note: To recover the ability to process RADIUS packets, a manual restart of the affected Policy Service Node (PSN) is required. See the Details section for more information.

Affected (16)

1 product
Identity Services Engine
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 2.2.0 patch17
Version 2.4.0 patch12
Version 2.4.0 patch13
Version 2.4.0 patch14
Version 2.6.0 patch10
Version 2.6.0 patch5
Version 2.6.0 patch6
Version 2.6.0 patch7
Version 2.6.0 patch8
Version 2.6.0 patch9
Version 2.7.0.356 patch1
Version 2.7.0 patch2
Version 2.7.0 patch3
Version 2.7.0 patch4
Version 3.0.0
Version 3.1

Related CWEs

Timeline

No history available yet.