Cisco IOx
cpe:2.3:a:cisco:iox:*:*:*:*:*:*:*, +1 more
A CRLF injection vulnerability has been identified in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software. This vulnerability allows an unauthenticated, remote attacker to exploit insufficient input validation by sending crafted packets to an affected device. Successful exploitation could enable the attacker to inject arbitrary log entries, manipulate log file structures, or obscure legitimate log events.
Exploitation of this vulnerability could lead to unauthorized log injection, log manipulation, and obscuring of genuine log events.
Cisco has released software updates to address this vulnerability. For guidance on upgrading, consult the Cisco IOS and IOS XE Software Security Advisory Bundled Publication or use the Cisco Software Checker tool to identify the first fixed release.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.