Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability
MonitorCVSS 5.3cisco-sa-ie1k-uxq86LnxAug 19, 2026
CiscoManufacturingTransportation
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A vulnerability in Cisco Industrial Ethernet 1000 Series Switches (versions 1.1 through 1.9.5) allows an unauthenticated remote attacker to cause a denial of service on the device manager, SSH, or API by sending high-rate ICMP, SSH, or HTTP traffic. This is due to insufficient protection against management plane flooding attacks. The attacker can cause the device's CPU to spike, rendering the management interface inaccessible while data traffic through the switch continues unaffected.
What this means
What could happen
An attacker could flood your IE 1000 Series Switch with traffic, making the management interface (web, SSH, or API) unavailable. Your operators would be unable to configure the switch or monitor its status, but data traffic through the switch would continue normally.
Who's at risk
Manufacturing and transportation facilities using Cisco Industrial Ethernet 1000 Series Switches for network management and control. Anyone who needs to remotely access switch configuration or monitoring capabilities through the web interface, SSH, or API should apply this patch.
How it could be exploited
An attacker sends a high rate of ICMP, SSH, or HTTP traffic to the switch's management interface from the network. This floods the management plane, consuming CPU resources until the device manager, SSH service, or API becomes unresponsive.
Prerequisites
- Network access to the switch's management interface (ICMP, SSH port 22, or HTTP/HTTPS management port)
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects management interface availability
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
Cisco Industrial Ethernet 1000 Series Switches1.1 through 1.9.5Fix available
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Cisco IE 1000 Series Switches to firmware version 1.10 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/dc5f4f2a-5138-4766-bfef-b93a90abc5a2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.