cisco-sa-webui-multi-ARNHM4v6: Cisco IOS XE Software Web-Based Management Interface Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco IOS XE Software could allow a remote attacker to read files from the underlying operating system, read limited parts of the configuration file, clear the syslog, or conduct a cross-site request forgery (CSRF) attack on an affected device, depending on their privilege level.For more information about these vulnerabilities, see the Details section of this advisory.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-multi-ARNHM4v6This advisory is part of the May 2025 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: May 2025 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of cisco-sa-webui-multi-ARNHM4v6?
The severity of cisco-sa-webui-multi-ARNHM4v6 is high due to potential remote file reading and CSRF vulnerabilities.
How do I fix cisco-sa-webui-multi-ARNHM4v6?
To fix cisco-sa-webui-multi-ARNHM4v6, update your Cisco IOS XE Software to the latest version provided by Cisco.
What types of attacks are possible with cisco-sa-webui-multi-ARNHM4v6?
cisco-sa-webui-multi-ARNHM4v6 may allow remote attackers to read files, access configuration file parts, clear syslogs, or perform CSRF attacks.
Which software versions are affected by cisco-sa-webui-multi-ARNHM4v6?
cisco-sa-webui-multi-ARNHM4v6 affects multiple versions of Cisco IOS XE Software.
How can I identify if my system is vulnerable to cisco-sa-webui-multi-ARNHM4v6?
To identify if your system is vulnerable to cisco-sa-webui-multi-ARNHM4v6, check for the presence of impacted Cisco IOS XE Software versions and their configurations.