CVE-2026-20084
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of ...
Affects 0 products across 2 vendors.
Software does not properly limit resource usage, allowing an attacker to exhaust CPU, memory, disk, or bandwidth.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition.
BSID: BS-2026-GLOBAL-063128-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-20084?
What is the CVSS score for CVE-2026-20084?
Is CVE-2026-20084 actively exploited?
How do I remediate CVE-2026-20084?
What systems are affected by CVE-2026-20084?
| CVE ID | CVE-2026-20084 |
|---|---|
| BSID | BS-2026-GLOBAL-063128-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
| Published | 2026-03-25 |
| Last Modified | 2026-03-26 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device. A successful exploit could allow an attacker to forward BOOTP packets from one VLAN to another, resulting in BOOTP VLAN leakage and potentially leading to high CPU utilization. This makes the device unreachable (either through console or remote management) and unable to forward traffic, resulting in a DoS condition. Note: This vulnerability can be exploited with either unicast or broadcast BOOTP packets. There are workarounds that address this vulnerability.
Source: NIST NVD / MITRE CVE Database
The vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP requests.
Exploitation Likelihood: HIGH
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 8cf41364422f6a8af1a758865fb4e34d8e2a9f4f48ec37ff7b93d105cd765703080c262fed3c231f76864764f5bf32b07a590ec3ffedc7ee9d88d573319ddcb7 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →