Cisco IOS XE Software for Catalyst 9000 Series Switches DHCP Snooping DoS (cisco-sa-bootp-WuBhNBxA)

high Nessus Plugin ID 331361

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco IOS-XE Software is affected by a vulnerability.

- A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device. A successful exploit could allow an attacker to forward BOOTP packets from one VLAN to another, resulting in BOOTP VLAN leakage and potentially leading to high CPU utilization. This makes the device unreachable (either through console or remote management) and unable to forward traffic, resulting in a DoS condition. Note: This vulnerability can be exploited with either unicast or broadcast BOOTP packets. (CVE-2026-20084)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCwq07617

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwq07617

http://www.nessus.org/u?b40d902b

http://www.nessus.org/u?cec1925e

Plugin Details

Severity: High

ID: 331361

File Name: cisco-sa-bootp-WuBhNBxA-iosxe.nasl

Version: 1.1

Type: Combined

Family: CISCO

Published: 7/31/2026

Updated: 7/31/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.3

Percentile: 96.43

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-20084

CVSS v3

Risk Factor: High

Base Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:cisco:ios_xe

Required KB Items: Host/Cisco/IOS-XE/Version, Host/Cisco/IOS-XE/Model

Patch Publication Date: 3/25/2026

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-20084

CISCO-SA: cisco-sa-bootp-WuBhNBxA

IAVA: 2026-A-0263

CISCO-BUG-ID: CSCwq07617