VDB
GCVE-110-NCSC-2025-297
GCVE-110-NCSC-2025-297
Advisory PublishedCVSS 6.5/10
A vulnerability in Cisco IOS and IOS XE Software's CLI allows authenticated local attackers to exploit a buffer overflow, potentially leading to unexpected device reloads and denial of service (DoS).
Weaknesses (CWE)
CWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-287Improper AuthenticationCWE-692Incomplete Denylist to Cross-Site ScriptingCWE-459Incomplete CleanupCWE-19-CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-35Path Traversal: '.../...//'CWE-232Improper Handling of Undefined ValuesCWE-805Buffer Access with Incorrect Length ValueCWE-284Improper Access ControlCWE-1287Improper Validation of Specified Type of InputCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-141Improper Neutralization of Parameter/Argument DelimitersCWE-121Stack-based Buffer Overflow
Risk Scores
CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Cisco | vers:unknown/* | — | — |
Browse GCVE Records
77,895 records in the GCVE database · Updated August 9, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.