Description
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Published: 2026-08-05
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the web‑based management interface of Cisco IOS XE Software allows an authenticated attacker with low privileges to trigger a denial‑of‑service by causing the device to reload. The vulnerability stems from inadequate error handling when the web interface processes a malformed certificate. Exploiting the weakness would result in a full system reboot, interrupting network services without exposing data or enabling further intrusion.

Affected Systems

Affected parties include any Cisco router, switch or device running Cisco IOS XE Software with the web UI enabled. The advisory does not list specific versions, so all releases of Cisco IOS XE Software are potentially vulnerable until a patch is released. The flaw is tied to the web‑based management interface and requires authentication, so only users who can log in remotely can abuse it.

Risk and Exploitability

The CVSS score of 6.3 classifies the vulnerability as a medium severity DoS. EPSS data is unavailable, and the flaw is not currently in CISA KEV. The attack vector is remote, authenticated, and requires low privilege, making it exploitable by anyone that can obtain valid credentials. A successful attack forces the device to reload, causing an outage that lasts until the router restarts.

Generated by OpenCVE AI on August 5, 2026 at 18:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cisco IOS XE to a release that contains the fix for the web UI DoS.
  • Restrict web‑based management interface access to a trusted network or VPN only.
  • Enforce strict certificate validation or disable malformed certificate authentication.

Generated by OpenCVE AI on August 5, 2026 at 18:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco ios Xe Software
Vendors & Products Cisco
Cisco ios Xe Software

Wed, 05 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Title Cisco IOS XE Software Web UI Denial of Service Vulnerability
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Cisco Ios Xe Software
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-05T17:45:12.182Z

Reserved: 2025-10-08T11:59:15.409Z

Link: CVE-2026-20311

cve-icon Vulnrichment

Updated: 2026-08-05T17:38:47.311Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-05T17:16:51.893

Modified: 2026-08-06T15:44:56.043

Link: CVE-2026-20311

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:15:07Z

Weaknesses