QID 316908

Date Published: 2021-03-30

QID 316908: Cisco IOS XE Software Web UI Denial of Service Vulnerabilities(cisco-sa-xe-webui-dos-z9yqYQAn)

QID Detection Logic (Authenticated):
The check matches Cisco IOS XE version retrieved via Unix Auth using "show version" command.
QID Detection Logic (Unauthenticated):
The check matches Cisco IOS XE version retrieved via SNMP or TCP/IP Fingerprint or NTP or Telnet.

Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-xe-webui-dos-z9yqYQAn for more information.

    CVEs related to QID 316908

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-xe-webui-dos-z9yqYQAn URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-z9yqYQAn