Denial of Service Vulnerability in Cisco IOS XE Software Management CLI
CVE-2026-20110
6.5MEDIUM
What is CVE-2026-20110?
A vulnerability in the Cisco IOS XE Software's command-line interface (CLI) allows an authenticated, local attacker to induce a denial of service condition on the device. This issue arises from misconfigured privileges tied to the 'start maintenance' command. Attackers with low-level access can leverage the CLI to execute this command, placing the device into maintenance mode and disabling interfaces. This can lead to a significant disruption in services. To recover from this state, device administrators must connect to the CLI and utilize the 'stop maintenance' command to restore normal operations.
Affected Version(s)
Cisco IOS XE Software 16.6.1
Cisco IOS XE Software 16.6.2
Cisco IOS XE Software 16.6.3