SB2026080629 - Denial of service in Cisco IOS XE SNMP



SB2026080629 - Denial of service in Cisco IOS XE SNMP

Published: August 6, 2026

Security Bulletin ID SB2026080629
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-20124)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper error handling in the Simple Network Management Protocol (SNMP) subsystem when parsing SNMP requests. A remote user can send a malformed SNMP request to cause a denial of service.

Successful exploitation causes the affected device to reload unexpectedly. The issue affects SNMP versions 1, 2c, and 3, and SNMP must be enabled on the device.


Remediation

Install update from vendor's website.