CVE-2026-20177: DoS via Management Plane Flooding on Cisco IE 1000 Switches
CVE-2026-20177 Published on August 19, 2026
Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability
A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding attacks. An attacker could exploit this vulnerability by sending a high rate of ICMP, SSH, or HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the CPU of the device to increase, resulting in a denial of service (DoS) condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected.
Vulnerability Analysis
CVE-2026-20177 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Affected Versions
Cisco Industrial Ethernet Switches:- Version 1.1 is affected.
- Version 1.2 is affected.
- Version 1.8.0 is affected.
- Version 1.8.2 is affected.
- Version 1.7.0 is affected.
- Version 1.3 is affected.
- Version 1.9.1 is affected.
- Version 1.6 is affected.
- Version 1.8.1 is affected.
- Version 1.9.2 is affected.
- Version 1.9.2a is affected.
- Version 1.9.3 is affected.
- Version 1.9.4 is affected.
- Version 1.9.5 is affected.