Cisco IOS XE Software TrustSec Protected Access Credential Provisioning Denial of Service Vulnerability
Description
A vulnerability in Cisco IOS XE TrustSec PAC provisioning allows unauthenticated remote attackers to cause a denial of service via a crafted RADIUS message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A vulnerability in Cisco IOS XE TrustSec PAC provisioning allows unauthenticated remote attackers to cause a denial of service via a crafted RADIUS message.
Vulnerability
The vulnerability resides in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software. It is due to improper validation of attributes in RADIUS messages. An unauthenticated, remote attacker can exploit this by sending a malicious RADIUS message to an affected device while the device is in a specific state, such as during PAC provisioning. Affected versions include Cisco IOS XE Software releases prior to the first fixed releases listed in the Cisco advisory [1].
Exploitation
An attacker does not require authentication or prior access to the device. The attacker must be able to send a crafted RADIUS message to the target device while the device is in a specific state (e.g., processing PAC provisioning). The exact sequence involves sending a malicious RADIUS message that triggers the improper validation, leading to a device reload. No user interaction is needed [1].
Impact
Successful exploitation causes a reload of the affected device, resulting in a denial of service (DoS) condition. The attacker gains no code execution, data access, or persistent compromise; the impact is limited to temporary service disruption [1].
Mitigation
Cisco has released software updates to address this vulnerability. For detailed information about affected and fixed software releases, consult the Cisco Security Advisory [1] and use the Cisco IOS Software Checker. No workarounds are available. Customers should upgrade to a fixed release as soon as possible [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190925-ctspac-dosmitrevendor-advisoryx_refsource_CISCO
News mentions
0No linked articles in our index yet.