cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1144
Views
3
Helpful
5
Replies

Cisco ISE 3.4p3 bug that replaces hidden values with asterisks?

Network Diver
Level 3
Level 3

Hi,

Today we had a fun experience with Cisco ISE 3.4 patch3. I was creating a new network device for AnyConnect to a Firepower 1120 and configured RADIUS and SNMP shared secret. We use ISE for authorization by group membership and for posture. After that on different two firewalls that are used for AnyConnect the remote access was no longer working. After a lot of debugging and swearing, I finally figured out, that ISE had replaced the shared secret and the SNMP 2c community strings with all asterisks.

Screenshot 2025-10-14 at 10.17.57.pngScreenshot 2025-10-14 at 10.18.01.png

I'm sure I'm not that stupid to paste all asterisks into two different network devices. Also the hide character used in the UI is "●" and not "*".

I found this one here, that looks similar, but this is from routers and wireless controllers: https://bst.cisco.com/quickview/bug/CSCvn14027

So is this another funky easter egg?

 

1 Accepted Solution

Accepted Solutions

Network Diver
Level 3
Level 3

Yup. Who needs hackers when Cisco can bring down systems all on its own?
https://bst.cisco.com/quickview/bug/CSCwn09816 

The bug description says it should be fixed in ISE 3.4 patch 2, but it still exists in patch 3.

View solution in original post

5 Replies 5

Network Diver
Level 3
Level 3

Yup. Who needs hackers when Cisco can bring down systems all on its own?
https://bst.cisco.com/quickview/bug/CSCwn09816 

The bug description says it should be fixed in ISE 3.4 patch 2, but it still exists in patch 3.

adn25
Level 1
Level 1

On a freshly setup ISE 3.4 patch 3 system this bug could not be reproduced. But we have a prod setup where we imported a ISE 3.1 backup. There the bug is reproduceable.

Network Diver
Level 3
Level 3

Workaround is to change the RADIUS secret on the firewall to the same number of asterisks than on ISE.

vmiraboronat
Level 1
Level 1

Another one here affected by this bug in v3.4 patch 3. Buggiest 'recommended' version ever for us. Happened at least in two network devices in the last month.

adn25
Level 1
Level 1

ISE 3.4 patch 4 was released on 4 November 2025 that should fix this issue. We were not courageous enough to install this very young patch.