CVE-2014-3276
published 2014-05-26CVE-2014-3276: Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
2.19%
80.3th percentile
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | <= 1.2 | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg88-5525-mfh3: Cisco Identity Services Engine (ISE) 1
ghsa_unreviewed·2022-05-17
CVE-2014-3276 [MEDIUM] GHSA-wg88-5525-mfh3: Cisco Identity Services Engine (ISE) 1
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.
Cisco
Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability
vendor_cisco·2014-05-22·CVSS 4.0
CVE-2014-3276 [MEDIUM] CWE-399 Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability
Cisco Identity Services Engine RADIUS Service Denial of Service Vulnerability
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to cause the affected system to stop processing Remote Authentication Dial-In User Service (RADIUS) packets.
The vulnerability is due to improper implementation of deadlock code when the system receives crafted RADIUS accounting packets from two different network access servers (NASs). An attacker could exploit this vulnerability by crafting RADIUS account packets and sending them to the affected system. An exploit could allow the attacker to cause the RADIUS process to become unresponsive, causing the affected system to stop processing RADIUS packets.
Cisco has confirmed the vulnerability in a security notice
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3276http://tools.cisco.com/security/center/viewAlert.x?alertId=34329http://www.securitytracker.com/id/1030274http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3276http://tools.cisco.com/security/center/viewAlert.x?alertId=34329http://www.securitytracker.com/id/1030274
2014-05-26
Published