First published: Wed Sep 27 2023(Updated: )
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device.This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS and IOS XE Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-webui-cmdij-FzZAeXAy is considered critical due to the potential for remote code execution.
To fix cisco-sa-webui-cmdij-FzZAeXAy, update your Cisco IOS XE software to the latest version that addresses this vulnerability.
Devices running the affected versions of Cisco IOS XE Software are vulnerable to cisco-sa-webui-cmdij-FzZAeXAy.
cisco-sa-webui-cmdij-FzZAeXAy is caused by insufficient input validation in the web UI of affected Cisco devices.
Yes, an authenticated remote attacker can exploit cisco-sa-webui-cmdij-FzZAeXAy to perform an injection attack.