SB2026080629 - Denial of service in Cisco IOS XE SNMP
Published: August 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-20124)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper error handling in the Simple Network Management Protocol (SNMP) subsystem when parsing SNMP requests. A remote user can send a malformed SNMP request to cause a denial of service.
Successful exploitation causes the affected device to reload unexpectedly. The issue affects SNMP versions 1, 2c, and 3, and SNMP must be enabled on the device.
Remediation
Install update from vendor's website.