Cisco SG350 and SG350X Series ... Note

Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability

A vulnerability exists in the SNMP subsystem of Cisco SG350 and SG350X switches. This vulnerability stems from inadequate error handling within the firmware when processing SNMP response data. An authenticated, remote attacker can exploit it by sending a specific SNMP request. Successfully exploiting this leads to an unexpected device reload, causing a denial of service. The vulnerability impacts SNMP versions 1, 2c, and 3. Exploitation requires either appropriate community strings (for v2c and earlier) or valid SNMP credentials (for v3). Cisco will not release software updates for these affected products due to their end-of-life status. PSIRT will continue to assess and disclose vulnerabilities until the end of support. No workarounds are available, but mitigation options may exist. The security impact is rated as high. This advisory is associated with CVE-2026-20185.