CVE-2023-20080: Cisco IOS

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries. An attacker could exploit this vulnerability by sending crafted DHCPv6 messages to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly.

Affected products

  • Cisco IOS: version 12.2(6)i1 only; version 15.1(2)sg only; version 15.1(2)sg1 only; version 15.1(2)sg2 only; version 15.1(2)sg3 only; version 15.1(2)sg4 only; …
  • Cisco IOS XE: version 3.3.0xo only; version 3.3.1xo only; version 3.3.2xo only; version 3.4.0sg only; version 3.4.1sg only; version 3.4.2sg only; …

Published 2023-03-23. Last modified 2026-06-17.