VDB

CISCO-SA-IOX-DOS-95FQNF7B

CISCO-SA-IOX-DOS-95FQNF7B PUBLISHED CVSS 5.300000190734863 MEDIUM

A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the Cisco IOx application hosting environment to stop responding. The IOx process will need to be manually restarted to recover services. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of the May 2025 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2025 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication ["https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75279"].

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
16.1.1
16.3.4
16.3.5
16.1.2
16.3.9
16.1.3
16.3.3
16.3.11
16.4.1
Cisco IOS
16.3.8
16.3.1
16.3.7
16.2.1
16.2.2
16.3.2
16.3.6
16.3.5b
16.3.10
16.3.1a

Timeline

  • May 7, 2025 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›