CVE-2026-20124: Cisco IOS XE Software SNMP Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20124?
CVE-2026-20124 has a severity rating of 7.7, which is classified as high.
How do I fix CVE-2026-20124?
To mitigate CVE-2026-20124, upgrade your Cisco IOS XE Software to the latest version that addresses this vulnerability.
What type of attack does CVE-2026-20124 enable?
CVE-2026-20124 allows an authenticated, remote attacker to execute a denial of service (DoS) attack on affected devices.
What software is affected by CVE-2026-20124?
CVE-2026-20124 affects the Cisco IOS XE Software.
What are the consequences of exploiting CVE-2026-20124?
Exploiting CVE-2026-20124 can cause the affected device to reload, leading to a denial of service condition.