CVE-2026-20177
Received Received - Intake

Management Plane Flooding DoS in Cisco IE 1000 Series Switches

Vulnerability report for CVE-2026-20177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding attacks. An attacker could exploit this vulnerability by sending a high rate of ICMP, SSH, or HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the CPU of the device to increase, resulting in a denial of service (DoS) condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco industrial_ethernet_1000_series_switches *
cisco industrial_ethernet_ie_1000_series_switches From 1.9.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Cisco Industrial Ethernet 1000 Series Switches. It allows an unauthenticated remote attacker to send high volumes of ICMP, SSH, or HTTP traffic to the device, causing CPU overload and a denial of service (DoS) condition. This makes the device manager web GUI, SSH, or API inaccessible, but data traffic through the device remains unaffected.

Detection Guidance

Monitor CPU usage on affected Cisco IE 1000 Series Switches for spikes during ICMP, SSH, or HTTP traffic. Use commands like 'show processes cpu' or 'show platform hardware qfp active infrastructure bqs all' to check CPU utilization. Enable logging for management plane traffic to detect unusual activity.

Impact Analysis

The impact includes loss of access to critical management functions like the web interface, SSH, or API for the affected Cisco switch. This can disrupt network management and monitoring, requiring physical intervention to restore functionality. Business operations relying on these switches may experience downtime.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing a denial of service (DoS) on management interfaces, potentially disrupting access to critical systems. GDPR requires maintaining availability of personal data processing systems, while HIPAA mandates secure and reliable access to protected health information systems. A DoS condition may violate these requirements by impairing system availability.

Mitigation Strategies

Upgrade affected Cisco IE 1000 Series Switches to fixed software releases (e.g., 1.9.6 or later) as soon as possible. Implement rate limiting for ICMP, SSH, and HTTP traffic to reduce management plane load. Monitor network traffic for signs of flooding attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20177. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart