Impact
The flaw involves improper control of a resource throughout its lifecycle, classified under CWE-664. Attackers able to exploit the flaw could maintain or manipulate a resource after it should have been released, enabling unauthorized access or persistence of malicious code. The impact could affect confidentiality, integrity, or availability of affected systems, depending on the resource at stake.
Affected Systems
Cisco IOS XE Software, all editions and versions that have not yet applied the recommended hardening releases. The CNA vendor list specifies only Cisco; no specific version range is disclosed, so all deploying IOS XE Software remain potentially vulnerable until patched.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. The EPSS score is not supplied, and the vulnerability is not listed in CISA KEV, indicating no documented exploitation cases yet. The attack vector is likely through any user or process that interacts with the affected resource, possibly requiring local or network access depending on the software component. Based on the description, it is inferred that exploitation may involve local code execution or privilege escalation if the resource pertains to privileged components.
OpenCVE Enrichment