Description
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.

This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.
Published: 2026-08-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the web‑based management interface of Cisco IOS XE Software allows an authenticated remote attacker with low privileges to trigger a denial of service by sending crafted input, causing the interface to become unresponsive. This flaw arises from insufficient input validation and is identified as an access control weakness (CWE‑269). The primary consequence is loss of availability for management operations, potentially disrupting network management and maintenance tasks.

Affected Systems

Based on the description, it is inferred that the vulnerability affects all versions of Cisco IOS XE Software until a patch is applied, because exact affected versions are not disclosed in the advisory.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. No EPSS score is available, so the current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated remote attacker with low privileges accessing the web-based management interface from trusted networks or VPNs. Because the flaw is purely a denial of service, attackers would aim to render the management interface unavailable rather than gain further credential escalation or data exfiltration.

Generated by OpenCVE AI on August 5, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Cisco IOS XE Software update that addresses this DoS issue as soon as it becomes available.
  • Limit access to the web‑based management interface to trusted users only and enforce least privilege permissions.
  • Monitor the web interface for unresponsiveness or errors; if the interface is unnecessary, consider disabling it or isolating it from exposed networks.

Generated by OpenCVE AI on August 5, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ios Xe Software
Vendors & Products Cisco
Cisco ios Xe Software

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.
Title Cisco IOS XE Software Web-Based Management Interface Vulnerability
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Cisco Ios Xe Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-05T17:45:13.732Z

Reserved: 2025-10-08T11:59:15.409Z

Link: CVE-2026-20308

cve-icon Vulnrichment

Updated: 2026-08-05T17:39:05.487Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:51.280

Modified: 2026-08-06T15:44:56.043

Link: CVE-2026-20308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:15:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management