📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Consumer Electronics and Retail MEDIUM 2h Global supply_chain Software Development and Technology HIGH 2h Global general Artificial Intelligence and Software Development LOW 3h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 4h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h Global general Consumer Electronics and Retail MEDIUM 2h Global supply_chain Software Development and Technology HIGH 2h Global general Artificial Intelligence and Software Development LOW 3h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 4h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h Global general Consumer Electronics and Retail MEDIUM 2h Global supply_chain Software Development and Technology HIGH 2h Global general Artificial Intelligence and Software Development LOW 3h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global malware Software Development / Technology HIGH 4h Global vulnerability Information Technology HIGH 4h Global data_breach Water Utilities / Critical Infrastructure HIGH 4h Global general Cybersecurity Services HIGH 5h Global data_breach Pharmaceutical HIGH 5h Global vulnerability Technology, Artificial Intelligence CRITICAL 6h
Vulnerabilities

CVE-2026-20083

Medium
A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition
CWE-235 — Weakness Type
Published: Mar 25, 2026  ·  Modified: Mar 28, 2026  ·  Source: NVD
CVSS v3
6.5
🔗 NVD Official
📄 Description (English)

A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper handling of a malformed SCP request. An attacker could exploit this vulnerability by issuing a crafted command through SSH. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.

🤖 AI Executive Summary

CVE-2026-20083 is a medium-severity denial of service vulnerability in Cisco IOS XE SCP server that allows authenticated local attackers to crash affected devices via malformed SCP requests over SSH. While exploit code is not publicly available and no patch exists yet, the vulnerability poses operational risk to Saudi organizations relying on Cisco networking equipment for critical infrastructure. Immediate mitigation through access controls and monitoring is essential pending vendor remediation.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 11, 2026 21:02
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi telecommunications operators (STC, Mobily, Zain), government agencies (NCA, CITC), banking sector (SAMA-regulated institutions), and energy companies (Saudi Aramco, SEC) that deploy Cisco IOS XE devices as core network infrastructure. The DoS impact could disrupt critical services, especially in government networks, financial transaction processing, and energy distribution systems. Organizations with Cisco ASR, ISR, and Catalyst switches are most at risk. The requirement for authenticated access slightly reduces exposure but remains critical for insider threat scenarios.
🏢 Affected Saudi Sectors
Telecommunications (STC, Mobily, Zain) Government (NCA, CITC, Ministry of Interior) Banking (SAMA-regulated institutions, Saudi National Bank) Energy (Saudi Aramco, SEC) Healthcare (MOH facilities) Education (Universities with Cisco infrastructure)
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all Cisco IOS XE devices in your environment using network discovery tools
2. Restrict SSH access to SCP-enabled devices to authorized administrators only via firewall rules and ACLs
3. Disable SCP server feature if not operationally required: 'no ip scp server enable'
4. Implement SSH key-based authentication and disable password authentication
5. Monitor for suspicious SCP requests in syslog and NetFlow data

Compensating Controls:
6. Deploy network segmentation to isolate management interfaces
7. Implement rate limiting on SSH connections to affected devices
8. Enable command accounting and logging for all SCP transactions
9. Configure device reload protection and watchdog timers
10. Establish baseline device behavior monitoring for unexpected reloads

Detection Rules:
- Alert on SSH connections from unexpected source IPs to SCP ports
- Monitor for malformed SCP protocol sequences in packet captures
- Track device reload events correlated with SSH session terminations
- Log all 'copy' and 'scp' commands executed on network devices
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة Cisco IOS XE في بيئتك باستخدام أدوات اكتشاف الشبكة
2. تقييد وصول SSH إلى الأجهزة المفعلة لـ SCP للمسؤولين المصرحين فقط عبر قواعد جدار الحماية وقوائم التحكم في الوصول
3. تعطيل ميزة خادم SCP إذا لم تكن مطلوبة تشغيليًا: 'no ip scp server enable'
4. تنفيذ المصادقة المستندة إلى مفتاح SSH وتعطيل المصادقة بكلمة المرور
5. مراقبة طلبات SCP المريبة في بيانات syslog و NetFlow

الضوابط التعويضية:
6. نشر تقسيم الشبكة لعزل واجهات الإدارة
7. تنفيذ تحديد معدل الاتصالات على اتصالات SSH للأجهزة المتأثرة
8. تفعيل محاسبة الأوامر والتسجيل لجميع معاملات SCP
9. تكوين حماية إعادة تحميل الجهاز وموقتات المراقبة
10. إنشاء مراقبة سلوك الجهاز الأساسي لعمليات إعادة التحميل غير المتوقعة

قواعد الكشف:
- تنبيه على اتصالات SSH من عناوين IP غير متوقعة إلى منافذ SCP
- مراقبة تسلسلات بروتوكول SCP المشوهة في التقاط الحزم
- تتبع أحداث إعادة تحميل الجهاز المرتبطة بإنهاء جلسات SSH
- تسجيل جميع أوامر 'copy' و 'scp' المنفذة على أجهزة الشبكة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies ECC 2024 A.8.1.1 - User Endpoint Devices ECC 2024 A.8.2.1 - Privileged Access Management ECC 2024 A.8.3.1 - Information Access Restriction
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Hardware Inventory SAMA CSF PR.AC-1 - Access Control Policy SAMA CSF PR.AC-4 - Access Rights Management SAMA CSF DE.CM-1 - Network Monitoring
🟡 ISO 27001:2022
ISO 27001:2022 A.5.3 - Segregation of Duties ISO 27001:2022 A.8.1.1 - User Registration and De-registration ISO 27001:2022 A.8.2.1 - User Access Provisioning ISO 27001:2022 A.8.3.1 - Access Rights Review
🟣 PCI DSS v4.0.1
PCI DSS 2.1 - Default Passwords PCI DSS 2.2.4 - Configure System Security Parameters PCI DSS 8.1 - Assign Unique ID to Each User
📊 CVSS Score
6.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeC — Changed
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity Medium
CVSS Score6.5
CWECWE-235
Exploit No
Patch ✗ No
Published 2026-03-25
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-235
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.