CVE-2014-3276: Cisco Identity Services Engine Software
Medium severity, CVSS 4.0. EPSS: 2.2% chance of exploitation in the next 30 days.
Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier does not properly handle deadlock conditions during reception of crafted RADIUS accounting packets from multiple NAS devices, which allows remote authenticated users to cause a denial of service (RADIUS outage) by sourcing these packets from two origins, aka Bug ID CSCuo56780.
Affected products
- Cisco Identity Services Engine Software: up to and including 1.2; version 1.0 only; version 1.1 only
Published 2014-05-26. Last modified 2026-06-17.