CVE-2025-20343

HIGH

Cisco Identity Services Engine - Denial of Service via RADIUS Request Processing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-20343. PoCs published by fevar54.

AI-analyzed exploit summary This repository contains a detailed writeup for CVE-2025-20343, a high-severity DoS vulnerability in Cisco ISE due to a logic error in RADIUS request handling. It describes how unauthenticated attackers can crash the device by sending crafted RADIUS packets.

Description

A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a MAC address that is already a rejected endpoint. An attacker could exploit this vulnerability by sending a specific sequence of multiple crafted RADIUS access request messages to Cisco ISE. A successful exploit could allow the attacker to cause a denial of service (DoS) condition when Cisco ISE restarts.

Exploits (1)

nomisec WRITEUP
by fevar54 · poc
https://github.com/fevar54/Blackash-CVE-2025-20343

This repository contains a detailed writeup for CVE-2025-20343, a high-severity DoS vulnerability in Cisco ISE due to a logic error in RADIUS request handling. It describes how unauthenticated attackers can crash the device by sending crafted RADIUS packets.

Classification
Writeup 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Cisco Identity Services Engine (ISE) versions 3.4.0, 3.4 Patch 1-3
No auth needed
Prerequisites: Network access to RADIUS port · Cisco ISE with RADIUS enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 8.6
EPSS 0.0066
EPSS Percentile 46.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-697
Status published
Products (1)
cisco/identity_services_engine 3.4.0 (4 CPE variants)
Published Nov 05, 2025
Tracked Since Feb 18, 2026