PT-2026-27794 · Cisco · Cisco Ios Xe

CVE-2026-20110

·

Publicado

2026-03-25

·

Atualizado

2026-03-30

CVSS v3.1

6.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cisco IOS XE Software (affected versions not specified)
Description A flaw exists in the Cisco IOS XE Software Command Line Interface (CLI) that could allow a local, authenticated attacker to trigger a denial of service (DoS) condition on a vulnerable device. The issue stems from improper privilege association with the start maintenance command. An attacker can exploit this by accessing the management CLI with limited privileges and executing the start maintenance command. Successful exploitation places the device into maintenance mode, disabling interfaces and resulting in a DoS condition. A device administrator can restore operations by connecting to the CLI and using the stop maintenance command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-06541
CVE-2026-20110

Produtos afetados

Cisco Ios Xe