Denial of Service Vulnerability in Cisco IOS XE Software's Web Management Interface
CVE-2026-20308
4.3MEDIUM
What is CVE-2026-20308?
A vulnerability exists within the web-based management interface of Cisco IOS XE Software that could enable an authenticated remote attacker with low privileges to execute a denial of service (DoS) attack. This issue arises from insufficient input validation. By sending specially crafted input to the web management interface, an attacker may trigger the interface to become unresponsive, disrupting management access to the device.
Affected Version(s)
Cisco IOS XE Software 17.2.1a
Cisco IOS XE Software 16.12.1y
Cisco IOS XE Software 16.12.3s