CVE-2019-1718: Cisco Identity Services Engine SSL Renegotiation Denial of Service Vulnerability
A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to trigger high CPU usage, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of Secure Sockets Layer (SSL) renegotiation requests. An attacker could exploit this vulnerability by sending renegotiation requests at a high rate. An successful exploit could increase the resource usage on the system, eventually leading to a DoS condition. This vulnerability affects version 2.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1718?
The severity of CVE-2019-1718 is rated as high due to its potential to cause a denial of service.
How do I fix CVE-2019-1718?
To mitigate CVE-2019-1718, updating to the patched version of Cisco Identity Services Engine is recommended.
What causes the CVE-2019-1718 vulnerability?
CVE-2019-1718 is caused by improper handling of SSL renegotiation in the web interface of Cisco Identity Services Engine.
Who is affected by CVE-2019-1718?
All users running Cisco Identity Services Engine version 2.1(0.907) are affected by CVE-2019-1718.
Can CVE-2019-1718 be exploited remotely?
Yes, CVE-2019-1718 can be exploited by an unauthenticated, remote attacker.