Cisco IOS XE Software SNMP DoS (cisco-sa-iosxe-snmp-dos-ZAqNm4MD)

high Nessus Plugin ID 333338

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco IOS XE Software is affected by a vulnerability.

- A vulnerability in the SNMP subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
(CVE-2026-20124)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCws90638

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCws90638

http://www.nessus.org/u?828308a5

Plugin Details

Severity: High

ID: 333338

File Name: cisco-sa-iosxe-snmp-dos-ZAqNm4MD-iosxe.nasl

Version: 1.1

Type: Combined

Family: CISCO

Published: 8/7/2026

Updated: 8/7/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 51.03

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-20124

CVSS v3

Risk Factor: High

Base Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:cisco:ios_xe

Required KB Items: Host/Cisco/IOS-XE/Version

Patch Publication Date: 8/5/2026

Vulnerability Publication Date: 8/5/2026

Reference Information

CVE: CVE-2026-20124

CWE: 772

CISCO-SA: cisco-sa-iosxe-snmp-dos-ZAqNm4MD

IAVA: 2026-A-0807

CISCO-BUG-ID: CSCws90638