{"id":"CVE-2026-20124","title":"A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r…","summary":"A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","cwe":["CWE-772"],"vendor":"cisco","product":"ios_xe","affected":["ios_xe = 3.13.9s","ios_xe = 3.13.10s","ios_xe = 3.16.6bs","ios_xe = 3.16.7as","ios_xe = 3.16.7bs","ios_xe = 3.16.7s","ios_xe = 3.16.8s","ios_xe = 3.16.9s","ios_xe = 3.16.10as","ios_xe = 3.16.10bs","ios_xe = 3.16.10s","ios_xe = 3.18.3asp","ios_xe = 3.18.3bsp","ios_xe = 3.18.3sp","ios_xe = 3.18.4s","ios_xe = 3.18.4sp","ios_xe = 3.18.5sp","ios_xe = 3.18.6sp","ios_xe = 3.18.7sp","ios_xe = 3.18.8asp","ios_xe = 3.18.9sp","ios_xe = 16.6.2","ios_xe = 16.6.3","ios_xe = 16.6.4","ios_xe = 16.6.4a","ios_xe = 16.6.4s","ios_xe = 16.6.5","ios_xe = 16.6.5a","ios_xe = 16.6.5b","ios_xe = 16.6.6","ios_xe = 16.6.7","ios_xe = 16.6.7a","ios_xe = 16.6.8","ios_xe = 16.6.9","ios_xe = 16.6.10","ios_xe = 16.7.1","ios_xe = 16.7.1a","ios_xe = 16.7.1b","ios_xe = 16.7.2","ios_xe = 16.7.3","ios_xe = 16.7.4","ios_xe = 16.8.1","ios_xe = 16.8.1a","ios_xe = 16.8.1b","ios_xe = 16.8.1c","ios_xe = 16.8.1d","ios_xe = 16.8.1e","ios_xe = 16.8.1s","ios_xe = 16.8.2","ios_xe = 16.8.3","ios_xe = 16.9.1","ios_xe = 16.9.1a","ios_xe = 16.9.1b","ios_xe = 16.9.1c","ios_xe = 16.9.1d","ios_xe = 16.9.1s","ios_xe = 16.9.2","ios_xe = 16.9.2a","ios_xe = 16.9.2s","ios_xe = 16.9.3","ios_xe = 16.9.3a","ios_xe = 16.9.3h","ios_xe = 16.9.3s","ios_xe = 16.9.4","ios_xe = 16.9.4c","ios_xe = 16.9.5","ios_xe = 16.9.5f","ios_xe = 16.9.6","ios_xe = 16.9.7","ios_xe = 16.9.8","ios_xe = 16.9.8a","ios_xe = 16.9.8b","ios_xe = 16.10.1","ios_xe = 16.10.1a","ios_xe = 16.10.1b","ios_xe = 16.10.1c","ios_xe = 16.10.1d","ios_xe = 16.10.1e","ios_xe = 16.10.1f","ios_xe = 16.10.1g","ios_xe = 16.10.1s","ios_xe = 16.10.2","ios_xe = 16.10.3","ios_xe = 16.11.1","ios_xe = 16.11.1a","ios_xe = 16.11.1b","ios_xe = 16.11.1c","ios_xe = 16.11.1s","ios_xe = 16.11.2","ios_xe = 16.12.1","ios_xe = 16.12.1a","ios_xe = 16.12.1c","ios_xe = 16.12.1s","ios_xe = 16.12.1t","ios_xe = 16.12.1w","ios_xe = 16.12.1x","ios_xe = 16.12.1y","ios_xe = 16.12.1z","ios_xe = 16.12.1z1","ios_xe = 16.12.1z2"],"published":"2026-08-05","updated":"2026-09-17","sourceUpdated":"2026-09-17T18:49:05.317","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20124","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD","label":"psirt@cisco.com"}],"tags":["nvd"],"epss":0.00353,"epssPercentile":0.28949,"ingestedAt":"2026-09-17T19:26:25.286Z","slug":"CVE-2026-20124","body":"## Overview\n\nA vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r\nThis vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP &mdash; Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.\n\n## Affected\n\n- `ios_xe = 3.13.9s`\n- `ios_xe = 3.13.10s`\n- `ios_xe = 3.16.6bs`\n- `ios_xe = 3.16.7as`\n- `ios_xe = 3.16.7bs`\n- `ios_xe = 3.16.7s`\n- `ios_xe = 3.16.8s`\n- `ios_xe = 3.16.9s`\n- `ios_xe = 3.16.10as`\n- `ios_xe = 3.16.10bs`\n- `ios_xe = 3.16.10s`\n- `ios_xe = 3.18.3asp`\n- `ios_xe = 3.18.3bsp`\n- `ios_xe = 3.18.3sp`\n- `ios_xe = 3.18.4s`\n- `ios_xe = 3.18.4sp`\n- `ios_xe = 3.18.5sp`\n- `ios_xe = 3.18.6sp`\n- `ios_xe = 3.18.7sp`\n- `ios_xe = 3.18.8asp`\n- `ios_xe = 3.18.9sp`\n- `ios_xe = 16.6.2`\n- `ios_xe = 16.6.3`\n- `ios_xe = 16.6.4`\n- `ios_xe = 16.6.4a`\n- `ios_xe = 16.6.4s`\n- `ios_xe = 16.6.5`\n- `ios_xe = 16.6.5a`\n- `ios_xe = 16.6.5b`\n- `ios_xe = 16.6.6`\n- `ios_xe = 16.6.7`\n- `ios_xe = 16.6.7a`\n- `ios_xe = 16.6.8`\n- `ios_xe = 16.6.9`\n- `ios_xe = 16.6.10`\n- `ios_xe = 16.7.1`\n- `ios_xe = 16.7.1a`\n- `ios_xe = 16.7.1b`\n- `ios_xe = 16.7.2`\n- `ios_xe = 16.7.3`\n- `ios_xe = 16.7.4`\n- `ios_xe = 16.8.1`\n- `ios_xe = 16.8.1a`\n- `ios_xe = 16.8.1b`\n- `ios_xe = 16.8.1c`\n- `ios_xe = 16.8.1d`\n- `ios_xe = 16.8.1e`\n- `ios_xe = 16.8.1s`\n- `ios_xe = 16.8.2`\n- `ios_xe = 16.8.3`\n- `ios_xe = 16.9.1`\n- `ios_xe = 16.9.1a`\n- `ios_xe = 16.9.1b`\n- `ios_xe = 16.9.1c`\n- `ios_xe = 16.9.1d`\n- `ios_xe = 16.9.1s`\n- `ios_xe = 16.9.2`\n- `ios_xe = 16.9.2a`\n- `ios_xe = 16.9.2s`\n- `ios_xe = 16.9.3`\n- `ios_xe = 16.9.3a`\n- `ios_xe = 16.9.3h`\n- `ios_xe = 16.9.3s`\n- `ios_xe = 16.9.4`\n- `ios_xe = 16.9.4c`\n- `ios_xe = 16.9.5`\n- `ios_xe = 16.9.5f`\n- `ios_xe = 16.9.6`\n- `ios_xe = 16.9.7`\n- `ios_xe = 16.9.8`\n- `ios_xe = 16.9.8a`\n- `ios_xe = 16.9.8b`\n- `ios_xe = 16.10.1`\n- `ios_xe = 16.10.1a`\n- `ios_xe = 16.10.1b`\n- `ios_xe = 16.10.1c`\n- `ios_xe = 16.10.1d`\n- `ios_xe = 16.10.1e`\n- `ios_xe = 16.10.1f`\n- `ios_xe = 16.10.1g`\n- `ios_xe = 16.10.1s`\n- `ios_xe = 16.10.2`\n- `ios_xe = 16.10.3`\n- `ios_xe = 16.11.1`\n- `ios_xe = 16.11.1a`\n- `ios_xe = 16.11.1b`\n- `ios_xe = 16.11.1c`\n- `ios_xe = 16.11.1s`\n- `ios_xe = 16.11.2`\n- `ios_xe = 16.12.1`\n- `ios_xe = 16.12.1a`\n- `ios_xe = 16.12.1c`\n- `ios_xe = 16.12.1s`\n- `ios_xe = 16.12.1t`\n- `ios_xe = 16.12.1w`\n- `ios_xe = 16.12.1x`\n- `ios_xe = 16.12.1y`\n- `ios_xe = 16.12.1z`\n- `ios_xe = 16.12.1z1`\n- `ios_xe = 16.12.1z2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}