← Back

CVE-2022-20937

nvd nist
Published: Nov 4, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources. An attacker could exploit this vulnerability by taking actions that cause Cisco ISE Software to receive specific RADIUS traffic. A successful and sustained exploit of this vulnerability could allow the attacker to cause reduced performance of the affected device, resulting in significant delays to RADIUS authentications. There are workarounds that address this vulnerability.

Affected (18)

1 product
Identity Services Engine
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 2.7.0
Version 2.7.0
Version 2.7.0 patch1
Version 2.7.0 patch2
Version 2.7.0 patch3
Version 2.7.0 patch4
Version 2.7.0 patch5
Version 2.7.0 patch6
Version 2.7.0 patch7
Version 3.0.0
Version 3.0.0 patch1
Version 3.0.0 patch2
Version 3.0.0 patch3
Version 3.0.0 patch4
Version 3.0.0 patch5
Version 3.1
Version 3.1 patch1
Version 3.1 patch3

Timeline

No history available yet.