Impact
The vulnerability stems from incorrect calculation logic in Cisco IOS XE Software, identified as CWE-682. This flaw can allow malicious input to bypass resource limits, potentially leading to memory exhaustion or other resource depletion that could disrupt service. The description notes multiple internally discovered issues addressed in a hardening release, but does not specify a remote attack vector. The impact is primarily a denial of service, with possible integrity or confidentiality loss if the resource exhaustion is exploited to facilitate other attacks. The CVSS score of 8.6 reflects a high severity for unmitigated vulnerabilities.
Affected Systems
Affected vendor and product are Cisco IOS XE Software across all versions prior to the hardening release, as seen in the advisory. The advisory references Cisco’s internal review and does not provide explicit version ranges, but any IOS XE build lacking the hardening patch is at risk.
Risk and Exploitability
Given the CVSS of 8.6 and the lack of EPSS data, exploitation likelihood is unclear. The vulnerability is not listed in CISA KEV, indicating no known widespread exploitation at the time of analysis. Attackers might target exposed devices, but without a documented vector or exploit, the risk remains theoretical. Administrative urgency remains, as mitigation should be applied promptly to preempt potential exploitation once exploit code becomes available.
OpenCVE Enrichment