CVE-2026-20084 Details
Description
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device. A successful exploit could allow an attacker to forward BOOTP packets from one VLAN to another, resulting in BOOTP VLAN leakage and potentially leading to high CPU utilization. This makes the device unreachable (either through console or remote management) and unable to forward traffic, resulting in a DoS condition. Note: This vulnerability can be exploited with either unicast or broadcast BOOTP packets. There are workarounds that address this vulnerability.
A denial-of-service vulnerability has been identified in the DHCP snooping feature of Cisco IOS XE Software, specifically on Catalyst 9000 Series Switches. This vulnerability allows an unauthenticated, remote attacker to manipulate BOOTP packets, causing them to be improperly forwarded between VLANs. The issue arises from inadequate handling of BOOTP requests, which can lead to BOOTP VLAN leakage and a significant increase in CPU utilization. As a result, the affected device becomes unreachable via console or remote management and fails to forward traffic, creating a denial-of-service condition. The vulnerability can be exploited using either unicast or broadcast BOOTP packets.
To address this vulnerability, Cisco has released software updates. For environments that do not need to handle BOOTP traffic, the command 'ip dhcp relay bootp ignore' can be configured on the affected device. Customers should evaluate the applicability and impact of this workaround in their own environments. For information on which Cisco software releases are vulnerable, consult the 'Fixed Software' section of the advisory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | New CVE Received | [email protected] |