Impact
A vulnerability in the web‑based management interface of Cisco IOS XE Software allows an authenticated remote attacker with low privileges to trigger a denial of service by sending crafted input, causing the interface to become unresponsive. This flaw arises from insufficient input validation and is identified as an access control weakness (CWE‑269). The primary consequence is loss of availability for management operations, potentially disrupting network management and maintenance tasks.
Affected Systems
Based on the description, it is inferred that the vulnerability affects all versions of Cisco IOS XE Software until a patch is applied, because exact affected versions are not disclosed in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. No EPSS score is available, so the current exploitation probability is unknown, and the vulnerability is not listed in CISA KEV. The likely attack vector is an authenticated remote attacker with low privileges accessing the web-based management interface from trusted networks or VPNs. Because the flaw is purely a denial of service, attackers would aim to render the management interface unavailable rather than gain further credential escalation or data exfiltration.
OpenCVE Enrichment