Cisco IOS XE Software
cpe:2.3:a:cisco:ios_xe:*:*:*:*:*:*:*, +1 more
A vulnerability exists in the web-based management interface of Cisco IOS XE Software, allowing authenticated, low-privileged, remote attackers to conduct injection attacks on affected devices. This issue arises from inadequate input validation, enabling attackers to send crafted input that could be exploited to read files from the underlying operating system.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the operating system.
Cisco has released software updates to address this vulnerability. Instructions for upgrading can be found on the Cisco Security Advisories page. Disabling the HTTP Server feature also eliminates the attack vector for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.