Impact
The vulnerability resides in Cisco IOS XE Software’s Blocks Extensible Exchange Protocol (BEEP) handling of SOAP requests. An unauthenticated, remote attacker can send a specially crafted BEEP SOAP message that the device parses improperly, which can trigger an unexpected reload of the system. The result is a denial of service that disrupts network services without requiring any credentials. The weakness is a lack of input validation during SOAP parsing, identified by CWE-388.
Affected Systems
Affected systems are Cisco IOS XE Software deployments. Version details are not specified in the advisory; affected releases include any IOS XE image that implements the BEEP feature and has not yet applied the vendor‑issued update. Administrators should consult the Cisco security advisory for precise version guidance.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no verified exploitation at this time. Attack vectors are remote over the network via the BEEP SOAP interface, and the flaw allows the attacker to cause a device reload without any authentication or special privileges. The potential impact remains a service interruption for the affected device.
OpenCVE Enrichment