Allocation of Resources Without Limits or Throttling in Industrial Ethernet 1000 Series Switches - CVE-2026-20177
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to insufficient protection against management plane flooding attacks in management plane packet handling when processing a high rate of ICMP, SSH, or HTTP traffic. A remote attacker can send a high rate of ICMP, SSH, or HTTP traffic to cause a denial of service.
Successful exploitation causes the device manager web GUI, SSH, or API to become inaccessible, while data traffic through the device is not affected.