Allocation of Resources Without Limits or Throttling in Industrial Ethernet 1000 Series Switches - CVE-2026-20177

 

Allocation of Resources Without Limits or Throttling in Industrial Ethernet 1000 Series Switches - CVE-2026-20177

Published: August 19, 2026


Vulnerability identifier: #VU144384
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20177
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to insufficient protection against management plane flooding attacks in management plane packet handling when processing a high rate of ICMP, SSH, or HTTP traffic. A remote attacker can send a high rate of ICMP, SSH, or HTTP traffic to cause a denial of service.

Successful exploitation causes the device manager web GUI, SSH, or API to become inaccessible, while data traffic through the device is not affected.


Affected software

Industrial Ethernet 1000 Series Switches

How to mitigate CVE-2026-20177

Install security update from vendor's website.

Industrial Ethernet 1000 Series Switches - update to 1.9.6

External References

Related Security Bulletins