---
id: CVE-2026-20124
title: "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r…"
summary: "A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r…"
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'
cwe:
  - CWE-772
vendor: cisco
product: ios_xe
affected:
  - ios_xe = 3.13.9s
  - ios_xe = 3.13.10s
  - ios_xe = 3.16.6bs
  - ios_xe = 3.16.7as
  - ios_xe = 3.16.7bs
  - ios_xe = 3.16.7s
  - ios_xe = 3.16.8s
  - ios_xe = 3.16.9s
  - ios_xe = 3.16.10as
  - ios_xe = 3.16.10bs
  - ios_xe = 3.16.10s
  - ios_xe = 3.18.3asp
  - ios_xe = 3.18.3bsp
  - ios_xe = 3.18.3sp
  - ios_xe = 3.18.4s
  - ios_xe = 3.18.4sp
  - ios_xe = 3.18.5sp
  - ios_xe = 3.18.6sp
  - ios_xe = 3.18.7sp
  - ios_xe = 3.18.8asp
  - ios_xe = 3.18.9sp
  - ios_xe = 16.6.2
  - ios_xe = 16.6.3
  - ios_xe = 16.6.4
  - ios_xe = 16.6.4a
  - ios_xe = 16.6.4s
  - ios_xe = 16.6.5
  - ios_xe = 16.6.5a
  - ios_xe = 16.6.5b
  - ios_xe = 16.6.6
  - ios_xe = 16.6.7
  - ios_xe = 16.6.7a
  - ios_xe = 16.6.8
  - ios_xe = 16.6.9
  - ios_xe = 16.6.10
  - ios_xe = 16.7.1
  - ios_xe = 16.7.1a
  - ios_xe = 16.7.1b
  - ios_xe = 16.7.2
  - ios_xe = 16.7.3
  - ios_xe = 16.7.4
  - ios_xe = 16.8.1
  - ios_xe = 16.8.1a
  - ios_xe = 16.8.1b
  - ios_xe = 16.8.1c
  - ios_xe = 16.8.1d
  - ios_xe = 16.8.1e
  - ios_xe = 16.8.1s
  - ios_xe = 16.8.2
  - ios_xe = 16.8.3
  - ios_xe = 16.9.1
  - ios_xe = 16.9.1a
  - ios_xe = 16.9.1b
  - ios_xe = 16.9.1c
  - ios_xe = 16.9.1d
  - ios_xe = 16.9.1s
  - ios_xe = 16.9.2
  - ios_xe = 16.9.2a
  - ios_xe = 16.9.2s
  - ios_xe = 16.9.3
  - ios_xe = 16.9.3a
  - ios_xe = 16.9.3h
  - ios_xe = 16.9.3s
  - ios_xe = 16.9.4
  - ios_xe = 16.9.4c
  - ios_xe = 16.9.5
  - ios_xe = 16.9.5f
  - ios_xe = 16.9.6
  - ios_xe = 16.9.7
  - ios_xe = 16.9.8
  - ios_xe = 16.9.8a
  - ios_xe = 16.9.8b
  - ios_xe = 16.10.1
  - ios_xe = 16.10.1a
  - ios_xe = 16.10.1b
  - ios_xe = 16.10.1c
  - ios_xe = 16.10.1d
  - ios_xe = 16.10.1e
  - ios_xe = 16.10.1f
  - ios_xe = 16.10.1g
  - ios_xe = 16.10.1s
  - ios_xe = 16.10.2
  - ios_xe = 16.10.3
  - ios_xe = 16.11.1
  - ios_xe = 16.11.1a
  - ios_xe = 16.11.1b
  - ios_xe = 16.11.1c
  - ios_xe = 16.11.1s
  - ios_xe = 16.11.2
  - ios_xe = 16.12.1
  - ios_xe = 16.12.1a
  - ios_xe = 16.12.1c
  - ios_xe = 16.12.1s
  - ios_xe = 16.12.1t
  - ios_xe = 16.12.1w
  - ios_xe = 16.12.1x
  - ios_xe = 16.12.1y
  - ios_xe = 16.12.1z
  - ios_xe = 16.12.1z1
  - ios_xe = 16.12.1z2
published: '2026-08-05'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:49:05.317'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20124'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD
    label: psirt@cisco.com
tags:
  - nvd
epss: 0.00353
epssPercentile: 0.2907
ingestedAt: '2026-09-17T19:26:25.286Z'
---

## Overview

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP &mdash; Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.

## Affected

- `ios_xe = 3.13.9s`
- `ios_xe = 3.13.10s`
- `ios_xe = 3.16.6bs`
- `ios_xe = 3.16.7as`
- `ios_xe = 3.16.7bs`
- `ios_xe = 3.16.7s`
- `ios_xe = 3.16.8s`
- `ios_xe = 3.16.9s`
- `ios_xe = 3.16.10as`
- `ios_xe = 3.16.10bs`
- `ios_xe = 3.16.10s`
- `ios_xe = 3.18.3asp`
- `ios_xe = 3.18.3bsp`
- `ios_xe = 3.18.3sp`
- `ios_xe = 3.18.4s`
- `ios_xe = 3.18.4sp`
- `ios_xe = 3.18.5sp`
- `ios_xe = 3.18.6sp`
- `ios_xe = 3.18.7sp`
- `ios_xe = 3.18.8asp`
- `ios_xe = 3.18.9sp`
- `ios_xe = 16.6.2`
- `ios_xe = 16.6.3`
- `ios_xe = 16.6.4`
- `ios_xe = 16.6.4a`
- `ios_xe = 16.6.4s`
- `ios_xe = 16.6.5`
- `ios_xe = 16.6.5a`
- `ios_xe = 16.6.5b`
- `ios_xe = 16.6.6`
- `ios_xe = 16.6.7`
- `ios_xe = 16.6.7a`
- `ios_xe = 16.6.8`
- `ios_xe = 16.6.9`
- `ios_xe = 16.6.10`
- `ios_xe = 16.7.1`
- `ios_xe = 16.7.1a`
- `ios_xe = 16.7.1b`
- `ios_xe = 16.7.2`
- `ios_xe = 16.7.3`
- `ios_xe = 16.7.4`
- `ios_xe = 16.8.1`
- `ios_xe = 16.8.1a`
- `ios_xe = 16.8.1b`
- `ios_xe = 16.8.1c`
- `ios_xe = 16.8.1d`
- `ios_xe = 16.8.1e`
- `ios_xe = 16.8.1s`
- `ios_xe = 16.8.2`
- `ios_xe = 16.8.3`
- `ios_xe = 16.9.1`
- `ios_xe = 16.9.1a`
- `ios_xe = 16.9.1b`
- `ios_xe = 16.9.1c`
- `ios_xe = 16.9.1d`
- `ios_xe = 16.9.1s`
- `ios_xe = 16.9.2`
- `ios_xe = 16.9.2a`
- `ios_xe = 16.9.2s`
- `ios_xe = 16.9.3`
- `ios_xe = 16.9.3a`
- `ios_xe = 16.9.3h`
- `ios_xe = 16.9.3s`
- `ios_xe = 16.9.4`
- `ios_xe = 16.9.4c`
- `ios_xe = 16.9.5`
- `ios_xe = 16.9.5f`
- `ios_xe = 16.9.6`
- `ios_xe = 16.9.7`
- `ios_xe = 16.9.8`
- `ios_xe = 16.9.8a`
- `ios_xe = 16.9.8b`
- `ios_xe = 16.10.1`
- `ios_xe = 16.10.1a`
- `ios_xe = 16.10.1b`
- `ios_xe = 16.10.1c`
- `ios_xe = 16.10.1d`
- `ios_xe = 16.10.1e`
- `ios_xe = 16.10.1f`
- `ios_xe = 16.10.1g`
- `ios_xe = 16.10.1s`
- `ios_xe = 16.10.2`
- `ios_xe = 16.10.3`
- `ios_xe = 16.11.1`
- `ios_xe = 16.11.1a`
- `ios_xe = 16.11.1b`
- `ios_xe = 16.11.1c`
- `ios_xe = 16.11.1s`
- `ios_xe = 16.11.2`
- `ios_xe = 16.12.1`
- `ios_xe = 16.12.1a`
- `ios_xe = 16.12.1c`
- `ios_xe = 16.12.1s`
- `ios_xe = 16.12.1t`
- `ios_xe = 16.12.1w`
- `ios_xe = 16.12.1x`
- `ios_xe = 16.12.1y`
- `ios_xe = 16.12.1z`
- `ios_xe = 16.12.1z1`
- `ios_xe = 16.12.1z2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
