Cisco Security Advisory
Follow
Cisco IOS XE Software SNMP Denial of Service Vulnerability
A critical vulnerability exists within the SNMP subsystem of Cisco IOS XE Software. This flaw allows authenticated, remote attackers to trigger a device reload, leading to a denial of service. The issue stems from incorrect error handling during the processing of SNMP requests. All SNMP versions, including 1, 2c, and 3, are susceptible to this vulnerability. Attackers can exploit this by sending a specially crafted SNMP request to an impacted device. Successful exploitation will cause the device to unexpectedly restart. To exploit this, an attacker needs valid SNMPv1 or v2c community strings or SNMPv3 user credentials. Cisco has already released software updates to fix this vulnerability. Unfortunately, there are no workarounds available, but a mitigation is in place. The security impact rating for this vulnerability is considered High.