HomeSecurityCisco patches high severity DoS vulnerability

Cisco patches high-severity DoS vulnerability

Cisco on Wednesday published ten security advisories, describing more than a dozen vulnerabilities in products , including two high-severity ones in the Identity Services Engine (ISE) and Unified Intelligence Center that could allow DoS.

See also: Google fixes vulnerability in Quick Share that causes DoS

Cisco DoS vulnerability

The flaw in ISE, with identifier CVE-2025-20152 , affects the RADIUS message processing function and can be exploited remotely , without authentication, causing ISE to restart and leading to a denial of service (DoS) condition.

The company also fixed another high-severity issue in Unified Intelligence Center, CVE -2025-20113, which could allow a certified attacker to gain elevated administrator privileges for a limited set of operations on the vulnerable system. This flaw was fixed along with CVE-2025-20114, a medium-severity vulnerability that can be exploited for privilege escalation.

See also: OpenSSH flaws expose SSH servers to MiTM and DoS attacks

Medium severity vulnerabilities were also patched in Webex, Webex Meetings, Secure Network Analytics Manager, Secure Network Analytics Virtual Manager, ISE, Duo, Unified Communications and Contact Center Solutions, and Unified Contact Center Enterprise (CCE) products.

Cisco patches high-severity DoS vulnerability
Cisco patches high-severity DoS vulnerability

Successful exploitation of these vulnerabilities could lead to XSS attacks, corruption of cached HTTP responses, arbitrary command execution, false results in analytics reports, arbitrary command injection, privilege escalation, and data tampering.

Cisco says that, to date, there is no evidence that any of these vulnerabilities have been actively exploited. More information is available on Cisco's security advisories page

See also: Multiple vulnerabilities in Cisco SNMP allow DoS attacks

Related to the above is how critical it is to regularly update and manage vulnerabilities in IT systems. Cisco's announcements show that even large technology providers with mature development processes can identify and fix significant security gaps in their products.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS