Denial of Service Vulnerability in Cisco IOS XE Software Management CLI
CVE-2026-20110

6.5MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
25 March 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2026-20110?

A vulnerability in the Cisco IOS XE Software's command-line interface (CLI) allows an authenticated, local attacker to induce a denial of service condition on the device. This issue arises from misconfigured privileges tied to the 'start maintenance' command. Attackers with low-level access can leverage the CLI to execute this command, placing the device into maintenance mode and disabling interfaces. This can lead to a significant disruption in services. To recover from this state, device administrators must connect to the CLI and utilize the 'stop maintenance' command to restore normal operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco IOS XE Software 16.6.1

Cisco IOS XE Software 16.6.2

Cisco IOS XE Software 16.6.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.