Cisco IOS XE Software for Catalyst 9000 Series Switches Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 7.4 Security Advisory

TL;DR 📌

A denial of service vulnerability has been identified in Cisco IOS XE Software for Catalyst 9000 Series Switches. An unauthenticated, adjacent attacker can exploit this vulnerability by sending crafted Ethernet frames, causing an egress port to drop all outbound traffic. The highest CVSS score is 7.4 (High). Cisco has released fixed software, but no workarounds are available.

What happened 🕵️‍♂️

A vulnerability exists in the handling of certain Ethernet frames within Cisco IOS XE Software for Catalyst 9000 Series Switches. This flaw allows an unauthenticated, adjacent attacker to send crafted Ethernet frames, which can block an egress port, resulting in a denial of service (DoS) condition. Once exploited, the affected port will drop all outbound traffic, severely impacting network operations.

Affected products 🖥️

The following products are affected if they are running a vulnerable release of Cisco IOS XE Software and have specific port configurations enabled:

  • Catalyst 9200 Series Switches
  • Catalyst 9300 Series Switches
  • Catalyst 9400 Series Switches
  • Catalyst 9500 Series Switches
  • Catalyst 9600 Series Switches
  • Meraki MS390 and Cisco Catalyst 9300 Series Switches (software earlier than Meraki CS 17.2.2)
  • Cloud-Managed Hybrid Operating Mode for Catalyst Wireless LAN Controllers (software earlier than Release 17.15.4)

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.
Cisco IOS XE Software Not specified

Workarounds 🧯

There are no workarounds available to mitigate this vulnerability.

Risk in context 🎯

The vulnerability has a CVSS score of 7.4, indicating a High risk. It is exploitable by unauthenticated, adjacent attackers, which means that an attacker must have physical or logical access to the local network. The impact is significant as it can lead to complete denial of service for affected ports. Immediate remediation is required through software updates.

Fast facts ⚡

  • Vulnerability: Denial of Service
  • CVSS Score: 7.4 (High)
  • Exploitation: Requires adjacent access, no authentication needed
  • Impact: Egress port drops all outbound traffic
  • Workarounds: None available
  • Fixed Software: Available, check Cisco Software Checker

For leadership 🧭

Executive summary. Switches in the Catalyst 9000 family, plus Meraki MS390 units and wireless controllers in cloud-managed hybrid mode, can have an egress port stop passing outbound traffic if an attacker on the adjacent network sends specially crafted Ethernet frames. There is no workaround, so the only path to resolution is upgrading affected devices, and this should be scheduled promptly given the operational impact of a dead port.

Why it matters:

  • Affects the entire Catalyst 9000 switch line (9200, 9300, 9400, 9500, 9600) plus Meraki MS390 and Catalyst 9300 switches on Meraki CS, and wireless controllers running Cloud-Managed Hybrid Operating Mode before Release 17.15.4
  • No authentication is needed and the attacker only needs adjacent (local network) access, not remote internet access, to trigger the fault
  • Once triggered, the affected egress port drops all outbound traffic, which can take down connectivity for everything downstream of that port
  • Cisco has confirmed there is no workaround or mitigating configuration, so exposure persists until the device is patched

Now / Next / Later:

  • Now: Identify which Catalyst 9000 switches, Meraki MS390 units, or hybrid-mode wireless controllers are in your estate and check their current software release against Cisco’s fixed versions.
  • Next: Schedule and apply the vendor-provided fixed software during your next maintenance window for every affected switch, Meraki device, and wireless controller identified.
  • Later: Add Cisco IOS XE and Meraki software versions to routine patch-tracking so releases addressing switch-level DoS issues are picked up and scheduled without waiting for a full audit cycle.