Executive brief
Cisco IOS and IOS XE devices with the XMCP (Extensible Messaging Client Protocol) Server feature enabled are vulnerable to remote denial of service attacks. An unauthenticated attacker can send a specially crafted network packet to cause the affected router or switch to crash and restart, disrupting all network traffic passing through that device. This vulnerability requires no authentication or user interaction.
Technical details
This vulnerability exists in the XMCP (Extensible Messaging Client Protocol, also called External Client protocol) implementation of Cisco IOS and IOS XE Software due to improper validation of malformed XMCP packets (CWE-606). An unauthenticated, remote attacker can exploit this by sending a crafted XMCP packet to a device with the XMCP Server feature enabled (configured via the "service-routing xmcp listen" command). A successful exploit causes the affected device to reload unexpectedly, resulting in a complete denial of service for all traffic transiting that device. No valid XMCP client credentials or prior access is required. Patches are available; Cisco also provides a temporary mitigation using access control lists to restrict XMCP connections to trusted clients only.
Affected products
- Cisco IOS Software Multiple versions with XMCP Server feature enabled (see Cisco Software Checker for specific releases)
- Cisco IOS XE Software Multiple versions with XMCP Server feature enabled (see Cisco Software Checker for specific releases)
Timeline
- 2026-08-05: disclosed: Vulnerability disclosed by Cisco