CVE-2014-3276

Cisco Identity Services Engine Software < 1.2 - Denial of Service via Crafted RADIUS Accounting Packets

Title source: llm
STIX 2.1

Description

Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030274

Scores

EPSS 0.0219
EPSS Percentile 80.6%

Details

CWE
CWE-399
Status published
Products (3)
cisco/identity_services_engine_software 1.0
cisco/identity_services_engine_software 1.1
cisco/identity_services_engine_software < 1.2
Published May 26, 2014
Tracked Since Feb 18, 2026