CVE-2026-20311

Cisco IOS XE Software Web UI Denial of Service Vulnerability

Severity
Medium 6.3
CVSS 3.1
Exploited
Not listed
EPSS
Discovered by
Vendor
Published by the vendor
Published
Aug 5, 2026
Assigned by cisco

Description

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Weakness: CWE-126

Affected products

Vendor Product Category Matched by
Cisco Cisco IOS XE Software Routing & Switching cna-assigner
Vendor-reported affected versions (1)
  • Cisco · Cisco IOS XE Software