A critical vulnerability in Cisco Identity Services Engine (ISE) could allow remote attackers to cause crash a system via a specially crafted sequence of RADIUS requests.

The CVE-2024-20399 is located in the way ISE handles repeated authentication failures from rejected endpoints, creating a denial-of-service that causes the system to reboot unexpectedly. The vulnerability results from a logic error in the RADIUS configuration, which rejects client requests after repeated failures.
See also: Critical RCE Vulnerability in Anthropic's Claude Desktop
Cisco ISE: How does the vulnerability work?
Attackers can exploit this flaw by sending specially crafted RADIUS access request messages, targeting MAC addresses that have already been marked as rejected endpoints. When ISE processes these malicious requests, the system crashes and restarts unexpectedly, disrupting authentication services across the entire network.

This type of attack does not require authentication credentials , making it particularly dangerous for organizations that rely on ISE for network access control and endpoint management. Cisco ISE versions 3.4.0 through 3.4 Patch 3 are vulnerable by default because the “ Reject RADIUS requests from clients with repeated failures ” setting is enabled by default in these versions.
See also: Critical vulnerabilities in Cisco Unified Contact Center Express
ISE acts as a central point for network access control, device authentication, and compliance policy enforcement. When ISE restarts unexpectedly, organizations lose visibility into network activity and may experience authentication failures for legitimate users and devices. This chain reaction can disrupt business operations across the entire network infrastructure.

Protection
Cisco has released multiple solutions to address this threat. Organizations can immediately disable the vulnerable RADIUS setting in the management console. However, Cisco recommends re-enabling it once the systems are updated with the fixes. ISE systems with version 3.4 should be upgraded to Patch 4 or later. It is noted that earlier versions (3.3 and below) and newer versions (3.5+) are not affected by this issue.
See also: Cisco: Hackers exploit ASA and FTD vulnerability
Administrators should check their ISE configuration at Administration > System > Settings > Protocols > RADIUS to verify their current status. The vulnerability only affects systems with the “repeated failure rejection” setting enabled, so disabling it provides temporary protection while upgrades are planned.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
