Cisco Identity Services Engine RADIUS Service DoS (cisco-sa-ise-dos-JLh9TxBp)

high Nessus Plugin ID 158584

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, a denial of service (DoS) vulnerability exists in Cisco Identity Services Engine due to improper handling of RADIUS requests. An unauthenticated, remote attacker can exploit this issue, by sending crafted RADIUS requests, to cause the RADIUS service to stop responding resulting in authorization / authentication timeouts.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvz77905

See Also

http://www.nessus.org/u?21a817e6

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz77905

Plugin Details

Severity: High

ID: 158584

File Name: cisco-sa-ise-dos-JLh9TxBp.nasl

Version: 1.10

Type: local

Family: CISCO

Published: 3/4/2022

Updated: 4/26/2022

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2022-20756

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/h:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine, cpe:/a:cisco:identity_services_engine_software

Required KB Items: Host/Cisco/ISE/version

Exploit Ease: No known exploits are available

Patch Publication Date: 3/2/2022

Vulnerability Publication Date: 3/2/2022

Reference Information

CVE: CVE-2022-20756

CWE: 399

CISCO-SA: cisco-sa-ise-dos-JLh9TxBp

IAVA: 2022-A-0100-S

CISCO-BUG-ID: CSCvz77905