Impact
A flaw in the web‑based management interface of Cisco IOS XE Software allows an authenticated attacker with low privileges to trigger a denial‑of‑service by causing the device to reload. The vulnerability stems from inadequate error handling when the web interface processes a malformed certificate. Exploiting the weakness would result in a full system reboot, interrupting network services without exposing data or enabling further intrusion.
Affected Systems
Affected parties include any Cisco router, switch or device running Cisco IOS XE Software with the web UI enabled. The advisory does not list specific versions, so all releases of Cisco IOS XE Software are potentially vulnerable until a patch is released. The flaw is tied to the web‑based management interface and requires authentication, so only users who can log in remotely can abuse it.
Risk and Exploitability
The CVSS score of 6.3 classifies the vulnerability as a medium severity DoS. EPSS data is unavailable, and the flaw is not currently in CISA KEV. The attack vector is remote, authenticated, and requires low privilege, making it exploitable by anyone that can obtain valid credentials. A successful attack forces the device to reload, causing an outage that lasts until the router restarts.
OpenCVE Enrichment