Impact
The vulnerability is an improper restriction of operations within the bounds of a memory buffer, consistent with CWE‑119. If successfully triggered, it could allow an attacker to overwrite memory and potentially execute arbitrary code or crash the affected device, thereby compromising confidentiality, integrity, and availability.
Affected Systems
Cisco IOS XE Software. No specific version range is listed in the advisory, so any device running the affected software stack may be at risk until the hardening release is applied.
Risk and Exploitability
The CVSS base score of 8.6 indicates a high‑severity flaw. While an EPSS score is not provided and the vulnerability is not listed in the CISA KEV catalog, the likely attack vector is inferred to be network‑based, based on the description of a buffer overflow, and would involve an attacker sending crafted inputs to exploit the bounds of a memory buffer. The lack of public exploit data does not reduce the risk, as similar vectors have been used historically to achieve remote code execution on network devices.
OpenCVE Enrichment