Junglewise Threat Intelligence

CVE-2026-20177: Cisco Industrial Ethernet 1000 Series denial of service in management plane

CVE-2026-20177 · Severity: medium · CVSS 5.3 · Published 2026-08-19

Vendors: Cisco.

Executive brief

Cisco Industrial Ethernet (IE) 1000 Series Switches are network infrastructure devices used to connect and manage industrial networks. An unauthenticated attacker can send a flood of ICMP, SSH, or HTTP traffic to render the device's management interface, SSH access, or API unavailable, disrupting administrative control of the switch. Data traffic flowing through the switch is not affected, but operational visibility and management are lost.

Technical details

This vulnerability (CWE-770: Allocation of Resources Without Limits or Throttling) exists in the handling of management plane packets on Cisco IE 1000 Series Switches. Insufficient rate limiting or filtering on management plane traffic allows an unauthenticated remote attacker to flood the device with ICMP, SSH, or HTTP packets, causing elevated CPU consumption. The attack requires only network reachability and no authentication; an attacker can exploit this by sending a high volume of management plane traffic to the affected device. A successful exploit denies service to the device manager web GUI, SSH, or API (AV:N/AC:L/PR:N). Cisco has released fixed software versions (1.9.6 and later for IE 1000 Series) to address this vulnerability.

Affected products

  • Cisco Industrial Ethernet 1000 Series Switches Earlier than 1.9.6 (fixed in 1.9.6 and later)

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed software versions available at time of publication

References