Cisco IOS and IOS XE Software SNMP Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software. This vulnerability allows an authenticated, remote attacker to cause an affected device to reload unexpectedly, leading to a DoS condition. The issue arises from improper error handling when parsing SNMP requests. Exploitation requires knowledge of a valid SNMP community string for SNMP v2c or earlier, or valid SNMP user credentials for SNMP v3.

Impact

Exploitation of this vulnerability causes the affected device to reload unexpectedly, creating a denial-of-service condition.

Remediation

Cisco plans to release software updates addressing this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco TAC. Until the vulnerability can be patched, administrators can disable vulnerable OIDs on affected devices, though this may impact SNMP-based device management. As a best practice, restrict SNMP access to trusted network devices.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.6
exploitability
4.9
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.