What happened
A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an HTTP request. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Affected versions
IOS: 15.2(6)E2; 15.2(7)E; 15.2(6)E2a; 15.2(6)E2b; 15.2(7)E1; 15.2(7)E0a; 15.2(7)E0b; 15.2(7)E0s; 15.2(6)E3; 15.2(7)E2; 15.2(7a)E0b; 15.2(7)E3; 15.2(7)E1a; 15.2(7b)E0b; 15.2(7)E2a; 15.2(7)E4; 15.2(7)E3k; 15.2(8)E; 15.2(8)E1; 15.2(7)E5; 15.2(7)E6; 15.2(8)E2; 15.2(7)E7; 15.2(8)E3; 15.2(7)E8; 15.2(8)E4; 15.2(7)E9; 15.2(8)E5; 15.2(7)E10 Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.