Cisco IOS Software Web UI Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the web user interface of Cisco IOS Software running on Industrial Ethernet Switches. This issue allows an authenticated, remote attacker with low privileges to cause the affected device to reload, creating a DoS condition. The vulnerability arises from improper input validation, enabling attackers to send crafted URLs in HTTP requests that trigger the device to reload.

Impact

Exploitation of this vulnerability causes the affected device to reload, leading to a denial-of-service condition.

Remediation

Cisco has released software updates to address this vulnerability. To determine the appropriate update, users can consult the Cisco Software Checker tool, which identifies fixed software releases. For devices running the vulnerable software, the HTTP Server feature can be disabled as a temporary mitigation until an upgrade is applied.

Added: Sep 24, 2025, 6:50 PM
Updated: Sep 24, 2025, 6:50 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
4.9
remediation
7.9
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.