Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c9q8-fg52-4crv

Опубликовано: 25 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.

This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.

This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.

EPSS

Процентиль: 21%
0.0029
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 5.3
nvd
5 месяцев назад

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.

CVSS3: 5.3
fstec
5 месяцев назад

Уязвимость веб-интерфейса платформы управления средой хостинга приложений Cisco IOx операционной системы Cisco IOS XE, позволяющая нарушителю манипулировать данными

EPSS

Процентиль: 21%
0.0029
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-93