漏洞标题
N/A
漏洞描述信息
Cisco身份服务引擎(ISE)的RADIUS消息处理特性中的一个漏洞可能导致未验证的远程攻击者停止受影响的系统处理RADIUS包。
这个漏洞是由于某些RADIUS accounting请求的不当处理引起的。攻击者可以通过向使用Cisco ISE进行身份验证、授权和计费(AAA)的网络访问设备(NAD)发送精心构造的身份验证请求来利用此漏洞。这最终导致NAD发送RADIUS accounting请求包到Cisco ISE。如果已知RADIUS共享密钥,攻击者还可以直接向Cisco ISE发送精心构造的RADIUS accounting请求包。成功利用此漏洞可能导致攻击者使RADIUS过程意外重启,导致身份验证或授权超时,并拒绝合法用户访问网络或服务。已经通过网络进行身份验证的客户端不会受到影响。
注意:要恢复处理RADIUS包的能力,可能需要手动重新启动受影响的政策服务节点(PSN)。更多详细信息,请参阅此建议的详细信息 ["#details"] 部分。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
漏洞类别
输入验证不恰当
漏洞标题
N/A
漏洞描述信息
A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the affected system to stop processing RADIUS packets.
This vulnerability is due to improper handling of certain RADIUS accounting requests. An attacker could exploit this vulnerability by sending a crafted authentication request to a network access device (NAD) that uses Cisco ISE for authentication, authorization, and accounting (AAA). This would eventually result in the NAD sending a RADIUS accounting request packet to Cisco ISE. An attacker could also exploit this vulnerability by sending a crafted RADIUS accounting request packet to Cisco ISE directly if the RADIUS shared secret is known. A successful exploit could allow the attacker to cause the RADIUS process to unexpectedly restart, resulting in authentication or authorization timeouts and denying legitimate users access to the network or service. Clients already authenticated to the network would not be affected.
Note: To recover the ability to process RADIUS packets, a manual restart of the affected Policy Service Node (PSN) may be required. For more information, see the Details ["#details"] section of this advisory.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
漏洞类别
资源管理错误
漏洞标题
Cisco Identity Services Engine 安全漏洞
漏洞描述信息
Cisco Identity Services Engine(ISE)是美国思科(Cisco)公司的一款环境感知平台(ISE身份服务引擎)。该平台通过收集网络、用户和设备中的实时信息,制定并实施相应策略来监管网络。 Cisco Identity Services Engine存在安全漏洞,该漏洞源于某些RADIUS记帐请求处理不当,可能允许未经身份验证的远程攻击者导致受影响的系统停止处理RADIUS数据包。
CVSS信息
N/A
漏洞类别
其他