Impact
The flaw lies in the handling of XMCP packets in Cisco IOS and IOS XE software. A malformed packet can trigger an application crash that causes the device to reload, resulting in a loss of service. The weakness is a failure to validate input (CWE‑606) and does not require authentication. The attack could lead to a total outage of the affected router or switch, impacting both local and remote network traffic.
Affected Systems
This vulnerability affects Cisco IOS and Cisco IOS XE software. Specific version information is not disclosed in the advisory, so all installations of these products that are not patched by Cisco are potentially exposed.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is remote; an unauthenticated attacker can send a crafted XMCP packet over the network to the target device. Likely exploitation requires only network access to the XMCP port and no credentials, making the threat practical for attackers who gain foothold in the same subnet or can reach the device externally.
OpenCVE Enrichment