Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-20308

CVE-2026-20308: 1 tracked advisory record across Cisco. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Cisco

1 advisory
  • Advisory severityMedium4.3

    Medium [CVE-2026-20308] Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

    cisco-sa-webui-dos-qdc7qx3Source published Source updated

    A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

    Affected products in this advisory
    • Aironet Access Point Software (IOS XE Controller)
    • IOS XE Catalyst SD-WAN
    • IOS XE Software Bootloader (ROMMON)
    • IOS XG Software

    1 more entries in the full advisory.

    Source-reported affected versions
    • Scope: At the time of publication, this vulnerability affected Cisco IOS XE Software if it had the web-based management interface enabled.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.
    Workarounds
    • There are no workarounds that address this vulnerability. However, there is a mitigation.
    • Disabling the HTTP Server feature eliminates the attack vector for these vulnerabilities and may be a suitable mitigation until affected devices can be upgraded. To disable the HTTP Server feature, use the no ip http server or no ip http secure-server command in global configuration mode. If both the HTTP server and HTTPS server are in use, both commands are required to disable the HTTP Server …
    • Allowing only trusted networks to access the HTTP server will limit exposure to these vulnerabilities. The following example shows how to allow remote access to the HTTP server from the trusted 192.168.10.0/24 network:
    • !

    6 more entries in the full advisory.

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery