Cisco IOS XE Software SNMP Denial of Service Vulnerability

MonitorCVSS 7.7cisco-sa-iosxe-snmp-dos-ZAqNm4MDAug 5, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in the SNMP subsystem of Cisco IOS XE Software allows an authenticated remote attacker to cause a device reload by sending a malformed SNMP request. The vulnerability stems from improper error handling when parsing SNMP requests across all SNMP versions (1, 2c, and 3). An attacker must have valid SNMPv1/v2c community strings or SNMPv3 user credentials to exploit this vulnerability. Successful exploitation results in a denial of service condition as the affected device reloads unexpectedly.

What this means
What could happen
An authenticated attacker with SNMP credentials could send a malformed SNMP request that crashes your Cisco router or switch, forcing it to reboot and disrupting network connectivity and any dependent operations.
Who's at risk
Network operators running Cisco IOS XE routers and switches (versions 16.10.1 through 3.18.8 that depend on SNMP for monitoring and management functions.
How it could be exploited
An attacker with valid SNMP community strings (SNMPv1/v2c) or SNMPv3 user credentials sends a specially crafted SNMP request to the device's SNMP port (typically UDP 161). The device's SNMP parser fails to handle the malformed request properly and triggers a device reload.
Prerequisites
  • Valid SNMPv1 or SNMPv2c read-only or read-write community string, or valid SNMPv3 user credentials
  • Network access to the device's SNMP port (UDP 161)
remotely exploitableauthenticated access requiredaffects network availabilitylow complexity attackhigh CVSS score (7.7)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (1)
ProductAffected VersionsFix Status
Cisco IOS XE Software SNMP16.10.1 through 3.18.9SPFix available
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGIf SNMP is not required, disable the SNMP service on all Cisco IOS XE devices
WORKAROUNDRestrict SNMP access to only trusted management networks using access control lists (ACLs) on UDP port 161
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Cisco IOS XE Software to version 3.18.9SP or later
HARDENINGUse strong SNMP community strings (SNMPv1/v2c) and rotate SNMPv3 credentials regularly
API: /api/v1/advisories/30385dc1-8389-4431-bb3b-e7f8c652d629

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.