4
CVSSv2

CVE-2014-3276

Published: 26/05/2014 Updated: 07/09/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and previous versions does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco identity services engine software

cisco identity services engine software 1.1

cisco identity services engine software 1.0

Vendor Advisories

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to cause the affected system to stop processing Remote Authentication Dial-In User Service (RADIUS) packets The vulnerability is due to improper implementation of deadlock code when the system receives crafted RADIUS accounting packets from two ...