Cisco IOS XE Software Simple Network Management Protocol Denial of Service Vulnerability

🚨 SEVERITY: HIGH — CVSS 7.7 Security Advisory

TL;DR 📌

A denial of service (DoS) vulnerability has been identified in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software. An authenticated remote attacker can exploit this vulnerability to cause affected devices to reload unexpectedly. The highest CVSS score for this vulnerability is 7.7, categorized as High severity. Cisco has released software updates to address this issue, but there are no workarounds available.

What happened 🕵️‍♂️

A vulnerability in the SNMP subsystem of Cisco IOS XE Software allows an authenticated remote attacker to send a specific SNMP request that can lead to a denial of service condition. This occurs due to improper error handling when processing the request, potentially causing the device to reload unexpectedly. The vulnerability affects SNMP versions 1, 2c, and 3, with different exploitation requirements based on the version used.

Affected products 🖥️

This vulnerability affects Cisco switches running a vulnerable release of Cisco IOS XE Software with the weighted early random detection (WRED) for Multiprotocol Label Switching (MPLS) experimental field configured and SNMP enabled. Cisco routing platforms running IOS XE Software are not affected.

Fixed software 🔧

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
1.0 Initial public release.
Cisco IOS and IOS XE Software Not specified

Workarounds 🧯

There are no workarounds that fully address this vulnerability. However, as a mitigation step, administrators can disable the affected object identifier (OID) on the device. It is recommended that SNMP access be restricted to trusted network devices.

Risk in context 🎯

With a CVSS score of 7.7, this vulnerability is rated as High risk. The exposure requires authenticated access, meaning that an attacker must know a valid SNMP community string or have valid SNMP user credentials. The potential for denial of service could impact device availability, making it critical for affected organizations to apply the necessary patches promptly.

Fast facts ⚡

  • Vulnerability: SNMP Denial of Service
  • CVSS Score: 7.7 (High)
  • Affected SNMP Versions: 1, 2c, and 3
  • Exploitation: Requires authenticated access
  • Impact: Device reload, resulting in DoS

For leadership 🧭

Executive summary. Switches running Cisco IOS XE with WRED configured for MPLS and SNMP enabled can be forced to reload by anyone holding a valid SNMP community string or user credentials, interrupting network availability. Given the high severity score and the fact that no workaround fully closes the gap, patching should be scheduled in the next available maintenance window.

Why it matters:

  • The flaw sits in the SNMP subsystem of Cisco IOS XE and is only present when WRED for MPLS experimental field is configured alongside SNMP, so exposure is tied directly to that specific switch configuration.
  • Exploitation needs valid SNMP credentials (a community string for v1/v2c or user credentials for v3), meaning anyone with legitimate or leaked SNMP access – not just an anonymous attacker – can trigger a reload.
  • Impact is a full device reload rather than degraded performance, which for switches carrying MPLS traffic means an abrupt loss of forwarding and management access.
  • Cisco routing platforms on IOS XE are unaffected, so remediation effort should be focused specifically on switch fleets rather than the whole IOS XE estate.

Now / Next / Later:

  • Now: Identify which Cisco IOS XE switches have WRED configured for the MPLS experimental field and SNMP enabled, and restrict SNMP access to a short list of trusted management hosts.
  • Next: Apply Cisco’s fixed IOS XE software release to all identified switches in the next change window, prioritising those reachable from broader management networks.
  • Later: Review SNMP community string and user credential handling across the switch estate, and where the specific OID mitigation is feasible, disable it on devices that cannot be patched immediately.