Resource exhaustion in Cisco IOS XE - CVE-2026-20084

 

Resource exhaustion in Cisco IOS XE - CVE-2026-20084

Published: March 25, 2026


Vulnerability identifier: #VU124585
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20084
CWE-ID: CWE-400
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of BOOTP packets in the DHCP snooping feature when processing BOOTP requests. A remote attacker can send a specially crafted BOOTP request packet to forward BOOTP packets between VLANs, resulting in high CPU utilization and a denial of service condition.

The affected device becomes unreachable through console or remote management and is unable to forward traffic. This vulnerability can be exploited with either unicast or broadcast BOOTP packets and requires specific configuration conditions: IP DHCP snooping enabled, ip helper-address configured on an SVI, the next hop being a sub-interface, and one of the sub-interfaces having the native VLAN configured.


Affected software

Cisco IOS XE

How to mitigate CVE-2026-20084

Install security update from vendor's website.

Cisco IOS XE - update to 17.12.6

External References

Related Security Bulletins