Cisco IOS and IOS XE HTTP Server Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E. This vulnerability allows an authenticated, remote attacker to cause an affected device to reload unexpectedly, leading to a DoS condition. The issue arises from improper validation of user-supplied input, enabling attackers to send malformed HTTP requests that cause a watchdog timer to expire, forcing the device to reload.

Impact

Exploitation of this vulnerability causes the device to reload unexpectedly, creating a denial-of-service condition.

Remediation

Cisco has released software updates to address this vulnerability. For guidance on upgrading to a fixed software release, consult the Cisco Security Vulnerability Policy or contact the Cisco Technical Assistance Center (TAC).

Added: Mar 25, 2026, 4:22 PM
Updated: Mar 25, 2026, 4:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
2.5
exploitability
4.9
remediation
7.7
relevance
4.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.