CVE-2026-20083 is a denial of service (DoS) vulnerability found in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software, stemming from improper handling of malformed SCP requests. An authenticated, low-privilege local attacker can exploit this with low complexity by issuing a crafted SSH command, leading to an unexpected device reload and a DoS condition, as indicated by its CVSS score of 6.5 Medium. There is currently no evidence of active exploitation, public exploit code availability, or significant community discussion, with its EPSS score suggesting a very low likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cisco | Cisco IOS XE Software | 16.10.1, 16.10.1a, 16.10.1b, 16.10.1c, 16.10.1d, 16.10.1e, 16.10.1f, 16.10.1g, 16.10.1s, 16.10.2, 16.10.3, 16.11.1, 16.11.1a, 16.11.1b, 16.11.1s, 16.11.2, 16.12.1, 16.12.10, 16.12.10a, 16.12.11, 16.12.12, 16.12.13, 16.12.14, 16.12.1a, 16.12.1c, 16.12.1s, 16.12.1t, 16.12.1w, 16.12.1x, 16.12.1y, 16.12.1z1, 16.12.1z2, 16.12.2, 16.12.2a, 16.12.2s, 16.12.3, 16.12.3a, 16.12.3s, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 16.12.5b, 16.12.6, 16.12.6a, 16.12.7, 16.12.8, 16.12.9, 16.6.1, 16.6.10, 16.6.2, 16.6.3, 16.6.4, 16.6.4a, 16.6.5, 16.6.5a, 16.6.6, 16.6.7, 16.6.8, 16.6.9, 16.7.1, 16.7.1a, 16.7.1b, 16.7.2, 16.7.3, 16.7.4, 16.8.1, 16.8.1a, 16.8.1b, 16.8.1c, 16.8.1d, 16.8.1e, 16.8.1s, 16.8.2, 16.8.3, 16.9.1, 16.9.1a, 16.9.1b, 16.9.1s, 16.9.2, 16.9.3, 16.9.3a, 16.9.4, 16.9.5, 16.9.5f, 16.9.6, 16.9.7, 16.9.8, 17.1.1, 17.1.1a, 17.1.1s, 17.1.1t, 17.1.3, 17.10.1, 17.10.1a, 17.10.1b, 17.11.1, 17.11.1a, 17.12.1, 17.12.1a, 17.12.1w, 17.12.1x, 17.12.1y, 17.12.1z, 17.12.1z1, 17.12.1z2, 17.12.1z3, 17.12.1z4, 17.12.2, 17.12.2a, 17.12.3, 17.12.3a, 17.12.4, 17.12.4a, 17.12.4b, 17.12.5, 17.12.5a, 17.12.5b, 17.12.5c, 17.12.5d, 17.12.6, 17.12.6a, 17.12.6b, 17.13.1, 17.13.1a, 17.14.1, 17.14.1a, 17.15.1, 17.15.1a, 17.15.1b, 17.15.1w, 17.15.1x, 17.15.1y, 17.15.1z, 17.15.2, 17.15.2a, 17.15.2b, 17.15.2c, 17.15.3, 17.15.3a, 17.15.3b, 17.15.4, 17.15.4d, 17.15.4e, 17.16.1, 17.16.1a, 17.17.1, 17.18.1, 17.18.1a, 17.18.1w, 17.2.1, 17.2.1a, 17.2.1r, 17.2.1v, 17.2.2, 17.2.3, 17.3.1, 17.3.1a, 17.3.1w, 17.3.1x, 17.3.1z, 17.3.2, 17.3.2a, 17.3.3, 17.3.4, 17.3.4a, 17.3.4b, 17.3.4c, 17.3.5, 17.3.5a, 17.3.5b, 17.3.6, 17.3.7, 17.3.8, 17.3.8a, 17.4.1, 17.4.1a, 17.4.1b, 17.4.2, 17.4.2a, 17.5.1, 17.5.1a, 17.6.1, 17.6.1a, 17.6.1w, 17.6.1x, 17.6.1y, 17.6.1z, 17.6.1z1, 17.6.2, 17.6.3, 17.6.3a, 17.6.4, 17.6.5, 17.6.5a, 17.6.6, 17.6.6a, 17.6.7, 17.6.8, 17.6.8a, 17.7.1, 17.7.1a, 17.7.1b, 17.7.2, 17.8.1, 17.8.1a, 17.9.1, 17.9.1a, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1y, 17.9.1y1, 17.9.2, 17.9.2a, 17.9.3, 17.9.3a, 17.9.4, 17.9.4a, 17.9.5, 17.9.5a, 17.9.5b, 17.9.5e, 17.9.5f, 17.9.6, 17.9.6a, 17.9.7, 17.9.7a, 17.9.7b, 17.9.8, 3.11.0S, 3.11.1S, 3.11.2S, 3.11.3S, 3.11.4S, 3.12.0S, 3.12.0aS, 3.12.1S, 3.12.2S, 3.12.3S, 3.12.4S, 3.13.0S, 3.13.0aS, 3.13.1S, 3.13.2S, 3.13.2aS, 3.13.3S, 3.13.4S, 3.13.5S, 3.13.5aS, 3.13.6S, 3.13.6aS, 3.13.7S, 3.14.0S, 3.14.1S, 3.14.2S, 3.14.3S, 3.14.4S, 3.15.0S, 3.15.1S, 3.15.1cS, 3.15.2S, 3.15.3S, 3.15.4S, 3.16.0S, 3.16.0cS, 3.16.1S, 3.16.1aS, 3.16.2S, 3.16.2aS, 3.16.2bS, 3.16.3S, 3.16.3aS, 3.16.4S, 3.16.4aS, 3.16.4bS, 3.16.4dS, 3.16.5S, 3.17.0S, 3.17.1S, 3.17.1aS, 3.17.2S, 3.17.3S, 3.18.0S, 3.18.0SP, 3.18.0aS, 3.18.1S, 3.18.1SP, 3.18.1aSP, 3.18.1bSP, 3.18.1cSP, 3.18.2S, 3.5.0E, 3.5.1E, 3.5.2E, 3.5.3E, 3.6.0E, 3.6.1E, 3.6.2E, 3.6.2aE, 3.6.3E, 3.6.4E, 3.6.5E, 3.6.5aE, 3.6.6E, 3.7.0E, 3.7.1E, 3.7.2E, 3.7.3E, 3.7.4E, 3.7.5E, 3.8.0E, 3.8.1E, 3.8.2E, 3.8.3E, 3.9.0E, 3.9.1ECNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cisco IOS XE Software Secure Copy Protocol Server Denial of Service Vulnerability
Mar 25, 2026Cisco IOS XE Software Secure Copy Protocol Server Denial of Service Vulnerability
Mar 25, 2026Cisco IOS XE Software Secure Copy Protocol Server Denial of Service Vulnerability
Mar 25, 2026