{"id":"CVE-2026-20308","title":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerabilit…","summary":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerabilit…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-269"],"vendor":"Cisco","product":"Cisco IOS XE Software","affected":["ios_xe_software 17.2.1a","ios_xe_software 16.12.1y","ios_xe_software 16.12.3s","ios_xe_software 16.12.1w","ios_xe_software 16.9.1d","ios_xe_software 17.3.1","ios_xe_software 16.9.4c","ios_xe_software 17.2.1","ios_xe_software 16.9.1b","ios_xe_software 16.9.2s","ios_xe_software 16.12.4","ios_xe_software 16.12.3a","ios_xe_software 17.1.1s","ios_xe_software 16.11.1a","ios_xe_software 16.11.1b","ios_xe_software 16.9.1s","ios_xe_software 16.9.3h","ios_xe_software 16.9.1c","ios_xe_software 16.10.1f","ios_xe_software 17.2.1v","ios_xe_software 16.9.3a","ios_xe_software 16.12.1a","ios_xe_software 16.12.1x","ios_xe_software 16.10.1c","ios_xe_software 16.12.3","ios_xe_software 16.11.2","ios_xe_software 16.12.2s","ios_xe_software 16.10.1b","ios_xe_software 16.9.6","ios_xe_software 16.9.2","ios_xe_software 16.10.1","ios_xe_software 16.12.1t","ios_xe_software 16.9.1","ios_xe_software 16.9.3s","ios_xe_software 16.12.2","ios_xe_software 16.11.1","ios_xe_software 16.9.3","ios_xe_software 16.11.1s","ios_xe_software 16.12.1","ios_xe_software 17.1.1","ios_xe_software 17.1.2","ios_xe_software 16.10.1d","ios_xe_software 17.1.1t","ios_xe_software 16.9.4","ios_xe_software 16.12.2t","ios_xe_software 16.9.5","ios_xe_software 16.10.1e","ios_xe_software 16.10.1a","ios_xe_software 16.12.1z","ios_xe_software 16.9.1a"],"published":"2026-08-05","updated":"2026-08-06","sourceUpdated":"2026-08-06T15:44:56.043","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20308","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3","label":"psirt@cisco.com"},{"url":"https://software.cisco.com"}],"tags":["nvd","cve.org","csaf","vendor-advisory","cisco"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-05T17:34:35.714176Z"},"ingestedAt":"2026-09-12T16:30:47.528Z","epss":0.0032,"epssPercentile":0.22207,"slug":"CVE-2026-20308","body":"## Overview\n\nA vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **cisco-sa-webui-dos-qdc7qx3** · Cisco · affected: Cisco Aironet Access Point Software (IOS XE Controller), Cisco IOS XE Catalyst SD-WAN, Cisco IOS XE Software (241 versions), Cisco IOS XE Software Bootloader (ROMMON), Cisco IOS XG Software, Cisco IOS XR Software · updated 2026-08-05 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3)","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}