Impact
The vulnerability stems from improper neutralization of special elements, categorized under CWE-74. This flaw permits an attacker to inject crafted input into the software’s processing pipeline. If successful, the attacker could potentially execute arbitrary commands or modify system behavior, thereby compromising the confidentiality and integrity of the device’s configuration.
Affected Systems
The affected product is Cisco IOS XE Software. Specific version ranges are not detailed in the advisory; therefore all releases of Cisco IOS XE prior to the hardening release are considered vulnerable and should be upgraded.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity, meaning that exploitation could have catastrophic effects. The EPSS score is not available, but nothing indicates a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote, as the flaw resides in a network-facing component. Successful exploitation would require the attacker to inject malicious data into a processing context, which is possible over the network. Due to the lack of additional mitigations, the risk remains high.
OpenCVE Enrichment