CVE-2019-1746: Cisco IOS

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation when processing CMP management packets. An attacker could exploit this vulnerability by sending malicious CMP management packets to an affected device. A successful exploit could cause the switch to crash, resulting in a DoS condition. The switch will reload automatically.

Affected products

  • Cisco IOS: version 12.1(6)ea1 only; version 12.1(6)ea1a only; version 12.1(6)ea2 only; version 12.1(6)ea2a only; version 12.1(6)ea2b only; version 12.1(6)ea2c only; …
  • Cisco IOS XE: version 3.2.0sg only; version 3.2.1sg only; version 3.2.2sg only; version 3.2.3sg only; version 3.2.4sg only; version 3.2.5sg only; …

Published 2019-03-28. Last modified 2026-06-17.