Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE unexpectedly

Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE unexpectedly

Posted on November 7, 2025November 7, 2025 By CWS

A important vulnerability in Cisco Id Companies Engine (ISE) may enable distant attackers to crash the system via a crafted sequence of RADIUS requests.

The flaw CVE-2024-20399, lies in how ISE handles repeated authentication failures from rejected endpoints, making a denial-of-service situation that forces surprising system restarts.

The vulnerability stems from a logic error within the RADIUS configuration that rejects shopper requests after repeated failures.

Attackers can exploit this by sending specifically crafted RADIUS entry request messages concentrating on MAC addresses already flagged as rejected endpoints.

Cisco Id Companies Engine Vulnerability

When ISE processes these malicious requests, the system crashes and restarts unexpectedly, disrupting authentication providers throughout the community.

Any such assault requires no authentication credentials, making it significantly harmful for organizations counting on ISE for community entry management and endpoint administration.

Cisco ISE variations 3.4.0 via 3.4 Patch 3 are weak by default as a result of the “Reject RADIUS requests from purchasers with repeated failures” setting is enabled by default in these releases.

CVE IDProductAffected VersionsCVSS v3.1 ScoreVulnerability TypeCVE-2024-20399Cisco ISE3.4.0, 3.4 P1, 3.4 P2, 3.4 P37.5Denial of Service (DoS)

ISE serves as a central level for community entry management, system authentication, and compliance coverage enforcement.

When ISE restarts unexpectedly, organizations lose visibility into community exercise and should expertise authentication failures for respectable customers and gadgets.

This cascading impact can disrupt enterprise operations throughout your complete community infrastructure. Cisco has launched a number of choices to deal with this risk.

Organizations can instantly flip off the weak RADIUS setting within the administration console. Nonetheless, Cisco recommends re-enabling it as soon as methods are patched.

ISE model 3.4 methods ought to be upgraded to Patch 4 or later. Notably, earlier variations (3.3 and under) and newer releases (3.5+) should not affected by this concern.

Directors ought to examine their ISE configuration at Administration > System > Settings > Protocols > RADIUS to confirm their present standing.

The vulnerability solely impacts methods with the repeated failures rejection setting enabled, so disabling it offers short-term safety whereas upgrades are deliberate.

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Attackers, Cisco, Engine, Identity, ISE, Restart, Services, unexpectedly, Vulnerability

Post navigation

Previous Post: Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares
Next Post: NVIDIA VApp for Windows Vulnerability Let Attackers Execute Malicious Code

Related Posts

Salat Stealer Exfiltrates Browser Credentials Via Sophisticated C2 Infrastructure Salat Stealer Exfiltrates Browser Credentials Via Sophisticated C2 Infrastructure Cyber Security News
Windows Imaging Component Vulnerability Can Lead to RCE Attacks Under Complex Attack Scenarios Windows Imaging Component Vulnerability Can Lead to RCE Attacks Under Complex Attack Scenarios Cyber Security News
Gujarat Teen Behind 50+ Cyberattacks During ‘Operation Sindoor’ Arrested Gujarat Teen Behind 50+ Cyberattacks During ‘Operation Sindoor’ Arrested Cyber Security News
Threat Actors Exploiting Expired Discord Invite Links to Deliver Multi-Stage Malware Threat Actors Exploiting Expired Discord Invite Links to Deliver Multi-Stage Malware Cyber Security News
New DNS Malware Detour Dog Delivers Strela Stealer Using DNS TXT Records New DNS Malware Detour Dog Delivers Strela Stealer Using DNS TXT Records Cyber Security News
CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenClaw Enhances AI Security with VirusTotal Partnership
  • OpenClaw v2026.2.6 Enhances Security and Model Support
  • Rising Threat of Cybersquatting in Cybersecurity
  • Enhancing Nmap Efficiency with nmapUnleashed
  • Claude Opus 4.6 Unveils 500+ Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenClaw Enhances AI Security with VirusTotal Partnership
  • OpenClaw v2026.2.6 Enhances Security and Model Support
  • Rising Threat of Cybersquatting in Cybersecurity
  • Enhancing Nmap Efficiency with nmapUnleashed
  • Claude Opus 4.6 Unveils 500+ Critical Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark