Impact
Cisco Industrial Ethernet 1000 Series Switches have a flaw in how they handle management plane packets. The insufficient protection against flooding allows an attacker who does not need authentication to overwhelm the device with a high‑rate stream of ICMP, SSH, or HTTP traffic. When the flood succeeds, the CPU usage spikes, causing the device manager web GUI, SSH port, or API to become unreachable. The flaw is a classic resource exhaustion type weakness and is classified as CWE‑770.
Affected Systems
The affected products are Cisco Industrial Ethernet 1000 Series Switches. No explicit firmware or model version ranges are supplied in the advisory, so all devices in the series are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate impact when the service is disrupted. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale exploitation campaigns have been documented yet. Likely privilege is remote and unauthenticated; the attacker only needs network connectivity to the management interfaces to send the flooding traffic. Successful exploitation does not affect data traffic on the device, but it renders the management stack unusable for configuration or monitoring.
OpenCVE Enrichment