Cisco IOS XE Software Web Based Management Interface Denial of Service (cisco-sa-xe-webui-dos-PtAODAWW)

medium Nessus Plugin ID 334511

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco IOS XE Software is affected by a vulnerability.

- A denial of service (DoS) vulnerability exists in the web-based management interface of Cisco IOS XE Software due to insufficient error handling. An authenticated, remote attacker can exploit this issue, via authenticating with a malformed certificate, to cause the affected device to stop responding.
(CVE-2026-20311)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCwu25287

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu25287

http://www.nessus.org/u?4d19e898

Plugin Details

Severity: Medium

ID: 334511

File Name: cisco-sa-xe-webui-dos-PtAODAWW-iosxe.nasl

Version: 1.1

Type: Combined

Family: CISCO

Published: 8/11/2026

Updated: 8/11/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 51.03

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Vector: CVSS2#AV:N/AC:H/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-20311

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:cisco:ios_xe

Required KB Items: Host/Cisco/IOS-XE/Version

Patch Publication Date: 8/5/2026

Vulnerability Publication Date: 8/5/2026

Reference Information

CVE: CVE-2026-20311

CISCO-SA: cisco-sa-xe-webui-dos-PtAODAWW

IAVA: 2026-A-0807

CISCO-BUG-ID: CSCwu25287