CVE-2026-20301
Received Received - Intake

Denial of Service in Cisco IOS XE Software

Vulnerability report for CVE-2026-20301, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco ios *
cisco ios_xe *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-606 The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in Cisco IOS and IOS XE Software's XMCP protocol handling. It allows an unauthenticated remote attacker to crash an affected device by sending a malformed XMCP packet, causing a denial of service (DoS) condition. The attacker does not need valid credentials to exploit this.

Detection Guidance

Detecting this vulnerability requires monitoring for malformed XMCP packets or unexpected device reloads. Use network monitoring tools to inspect XMCP traffic for anomalies. Check device logs for reload events or error messages related to XMCP packet handling. Enable packet capture on affected devices to analyze incoming XMCP traffic for malformed packets.

Impact Analysis

If exploited, this vulnerability could cause your Cisco device to reload unexpectedly, disrupting network services and leading to downtime. It may affect availability of critical systems relying on the vulnerable device.

Compliance Impact

This vulnerability could impact compliance with standards like GDPR and HIPAA by causing disruptions in network availability due to denial of service conditions. Unplanned device reloads may lead to service interruptions, potentially affecting data processing or access, which are critical under these regulations.

Mitigation Strategies

Immediately upgrade affected Cisco IOS or IOS XE devices to fixed software releases provided by Cisco. If upgrading is not feasible, configure an access control allow list to restrict XMCP connections to trusted clients only. Disable the XMCP Server feature if it is not required for operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20301. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart