CVE-2025-20343

CWE-6974 documents4 sources
Severity
7.5HIGH
EPSS
0.4%
top 37.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 5

Description

A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a MAC address that is already a rejected endpoint. An attacker could exploit this vulnerability by sending a specific sequence of multiple crafted RADIUS access request messages to Ci

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
Cisco Identity Services Engine Radius Suppression Denial of Service Vulnerability2025-11-05
GHSA
GHSA-cfwq-p5hw-9v6p: A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow a2025-11-05

📋Vendor Advisories

1
Cisco
Cisco Identity Services Engine RADIUS Suppression Denial of Service Vulnerability2025-11-05
CVE-2025-20343 (HIGH CVSS 7.5) | A vulnerability in the RADIUS setti | cvebase.io