Cisco released urgent patches for a critical authentication‑bypass vulnerability in its Identity Services Engine that has been exploited in the wild as a zero‑day.
Cisco has issued emergency patches for a critical authentication‑bypass flaw in its Identity Services Engine (ISE) after confirming active exploitation in the wild, marking the first known zero‑day attack on the platform.
Vulnerability Overview
The flaw, tracked as CVE‑2024‑XXXX, allows unauthenticated attackers to bypass ISE’s authentication mechanisms and gain administrative access to the management console. The vulnerability resides in the handling of malformed RADIUS packets, enabling remote code execution without requiring valid credentials.
Active Exploitation Details
Security researchers observed threat actors leveraging the vulnerability within days of its discovery, targeting organizations that rely on ISE for network access control. Exploits were delivered via crafted authentication requests, allowing attackers to harvest privileged tokens and pivot to other network resources.
Cisco’s incident response team worked with customers and third‑party partners to confirm the exploit’s presence in multiple botnet campaigns. The rapid escalation prompted the company to release an out‑of‑band patch ahead of its regular update cycle.
Cisco’s Emergency Response
Cisco published advisory CISCO‑SEC‑2024‑XXX, providing patches for ISE versions 2.9 and later. The advisory includes detailed mitigation steps, such as disabling the vulnerable RADIUS service temporarily and applying the latest software releases as soon as possible.
- Download the official patch from Cisco’s Security Advisory portal
- Verify ISE version compatibility before installation
- Restart the ISE services after patching
- Monitor logs for any suspicious authentication attempts
Recommendations for Administrators
Organizations should prioritize patch deployment, enforce strong network segmentation, and enable multi‑factor authentication for administrative accounts. Additionally, reviewing RADIUS traffic for anomalies can help detect lingering exploitation attempts.
“The rapid exploitation of this ISE zero‑day underscores the need for continuous monitoring and swift patch management in network security environments,” said a Cisco security engineer.
For a complete overview of the vulnerability, patch details, and mitigation guidance, see the original SecurityWeek coverage of the Cisco ISE zero‑day.
SecurityWeek coverage of Active Exploitation Triggers Emergency Patch for Cisco ISE Zero‑Day