Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
Plan PatchCVSS 8.6cisco-sa-ios-xmcp-thbAr34tAug 5, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A vulnerability in the Extensible Messaging Client Protocol (XMCP, also called External Client protocol) in Cisco IOS and IOS XE Software allows an unauthenticated remote attacker to cause a denial of service by sending a malformed XMCP packet. Successful exploitation causes the affected device to reload unexpectedly, interrupting service. No XMCP client credentials are required. Cisco has released software updates to address this vulnerability. No workarounds exist, but mitigation is available.
What this means
What could happen
An attacker could send a crafted network packet to a Cisco router or switch running affected IOS or IOS XE software, causing it to crash and reload unexpectedly. This would interrupt all traffic routing and switching until the device comes back online, taking down network connectivity for any connected segments.
Who's at risk
Organizations operating Cisco IOS or IOS XE-based routers and switches (including ISR, ASR, Catalyst, and Nexus devices) used in network core, distribution, or edge positions. Any facility with critical routing or switching infrastructure depends on these devices remaining stable.
How it could be exploited
An attacker with network access to an affected Cisco device would send a specially crafted XMCP (External Client protocol) packet to the device. The device improperly handles this malformed packet, triggering a crash and reload. No authentication or user credentials are required—the attacker just needs the network path to reach the device.
Prerequisites
- Network access to the device running XMCP (port 3000 or configured XMCP port)
- The XMCP service must be enabled on the affected device
- No authentication credentials required
remotely exploitableno authentication requiredlow complexityhigh CVSS score (8.6)affects network availability and critical infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol12.2(6)I1 through 3.8.9EFix available
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDIf immediate patching is not possible, restrict network access to XMCP port (default 3000) at network perimeter and internal firewalls to only trusted management networks
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Cisco IOS or IOS XE software to version 3.9.0 or later
Long-term hardening
0/1HARDENINGDisable XMCP service if it is not actively used for management purposes
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0c20f97c-6bb7-4f51-b886-d120a4b2952fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.