Security Advisory Desk
highQCS priority 100/100Cisco

Cisco IOS XE Software SNMP Denial of Service Vulnerability

A security flaw in Cisco IOS XE software's SNMP system can let someone with login access crash the device remotely, causing it to restart unexpectedly and disrupt service. This happens because the software doesn't correctly handle certain bad SNMP messages. An attacker could trigger this by sending a malformed SNMP request if they have valid SNMP credentials. Cisco has released updates to fix this problem. There are no simple workarounds, but administrators can apply a mitigation to reduce the risk.

Published 5/8/2026, 4:00:00 pmVerified 6/8/2026, 12:59:50 amRevision 1
Cisco high network security advisory visual

In plain language

What this advisory means

A security flaw in Cisco IOS XE software's SNMP system can let someone with login access crash the device remotely, causing it to restart unexpectedly and disrupt service. This happens because the software doesn't correctly handle certain bad SNMP messages. An attacker could trigger this by sending a malformed SNMP request if they have valid SNMP credentials. Cisco has released updates to fix this problem. There are no simple workarounds, but administrators can apply a mitigation to reduce the risk.

Technical explanation

How the issue affects the environment

The vulnerability arises from improper error handling in the SNMP subsystem of Cisco IOS XE Software when parsing malformed SNMP requests. It affects all SNMP versions 1, 2c, and 3. Exploiting this issue requires authentication: the attacker must possess either SNMPv1 or v2c community strings with read-only or read-write access, or valid SNMPv3 user credentials. Upon receiving a crafted malformed SNMP message, the affected device may reload unexpectedly, causing a denial of service. No workaround fully mitigates the issue; however, administrators can mitigate exposure by disabling specific Object Identifiers (OIDs) via SNMP server view configurations. Cisco has provided software updates that fully remediate the vulnerability.

Operational impact

Why teams should care

Successful exploitation of this vulnerability causes devices running Cisco IOS XE with SNMP enabled to reload unexpectedly, leading to denial of service conditions. This can result in network downtime, impacting business operations that rely on the affected network devices. Since no workarounds completely resolve the issue, organizations must apply Cisco's mitigation or upgrade to fixed software to maintain service continuity and security.

Immediate action

Cisco has released software updates that address this vulnerability. Customers should upgrade to the fixed software releases as soon as they are available. Meanwhile, administrators can apply the provided mitigation by disabling specific SNMP OIDs using the "snmp-server view" configuration commands to reduce exposure. Customers using Meraki cloud-managed switches should contact Meraki support for mitigation assistance.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

There are no workarounds that fully address this vulnerability. However, mitigation is possible by disabling affected SNMP OIDs through configuration changes to restrict SNMP access and prevent exploitation. This mitigation may affect some device management functions via SNMP, such as discovery and inventory.

Evidence and validation checklist

  • Vulnerability affects Cisco IOS XE SNMP subsystem due to improper error handling when parsing SNMP requests.
  • Affects SNMP versions 1, 2c, and 3.
  • Exploitation requires authenticated access with SNMPv1/v2c community string or SNMPv3 credentials.
  • Malformed SNMP request can cause device reload leading to denial of service.
  • Cisco released software updates to fix the issue.
  • No full workarounds are available; mitigation involves disabling affected OIDs via SNMP server view configuration.
  • Cisco PSIRT has no knowledge of public exploitation at this time.

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source