CyberRota Analysis
AI-GeneratedA vulnerability in the SNMP subsystem of Cisco IOS XE Software allows an authenticated remote attacker to exploit improper error handling, potentially leading to a denial of service (DoS) by causing the affected device to unexpectedly reload. This issue impacts all versions of SNMP (1, 2c, and 3), and exploitation requires valid SNMP community strings or credentials. Organizations using Cisco devices with SNMP enabled should prioritize patching to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.