VendorsCiscoasr_1006all versions
Vulnerabilities

Cisco ASR 1006

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

69CVEs
CVE-2021-1529
Cisco IOS XE SD-WAN Software Command Injection Vulnerability
Published 2021-10-21 · Modified
7.8EPSS 0.003
CVE-2023-20065
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Cisco IOx application container. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Published 2023-03-23 · Modified
7.8EPSS 0.002
CVE-2020-3428
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WLAN Local Profiling Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2020-3511
Cisco IOS and IOS XE Software ISDN Q.931 Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2020-3508
Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2021-1621
Cisco IOS XE Software Interface Queue Wedge Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2022-20851
Cisco IOS XE Software Web UI Command Injection Vulnerability
Published 2022-09-30 · Modified
7.2EPSS 0.010
CVE-2020-3423
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.004
CVE-2021-34725
Cisco IOS XE SD-WAN Software Command Injection Vulnerability
Published 2021-09-23 · Modified
7.2EPSS 0.004
CVE-2020-3214
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.004
CVE-2020-3396
Cisco IOS XE Software IOx Guest Shell USB SSD Namespace Protection Privilege Escalation Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.003
CVE-2017-12319
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.
Published 2018-03-27 · Analyzed
7.1KEVEPSS 0.052
CVE-2018-0179
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
Published 2018-03-28 · Analyzed
7.1KEVEPSS 0.049
CVE-2018-0180
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
Published 2018-03-28 · Analyzed
7.1KEVEPSS 0.049
CVE-2013-1167
Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled during the processing of encapsulation, aka Bug ID CSCtt11558.
Published 2013-04-11 · Modified
7.1EPSS 0.020
CVE-2015-0688
Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.
Published 2015-04-04 · Modified
7.1EPSS 0.017
CVE-2020-3524
Cisco IOS XE ROM Monitor Software Vulnerability
Published 2020-09-24 · Modified
6.9EPSS 0.003
CVE-2021-34723
Cisco IOS XE SD-WAN Software Arbitrary File Overwrite Vulnerability
Published 2021-09-23 · Modified
6.9EPSS 0.002
CVE-2012-5017
Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.
Published 2014-04-23 · Modified
6.8EPSS 0.015
CVE-2023-20081
Cisco Adaptive Security Appliance Software, Firepower Threat Defense Software, IOS Software, and IOS XE Software IPv6 DHCP (DHCPv6) Client Denial of Service Vulnerability
Published 2023-03-23 · Modified
6.8EPSS 0.007
CVE-2021-34724
Cisco IOS XE SD-WAN Software Privilege Escalation Vulnerability
Published 2021-09-23 · Modified
6.6EPSS 0.003
CVE-2017-12232
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.
Published 2017-09-28 · Analyzed
6.5KEVEPSS 0.022
CVE-2023-20066
Cisco IOS XE Software Web UI Path Traversal Vulnerability
Published 2023-03-23 · Modified
6.5EPSS 0.017
CVE-2014-2183
The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
Published 2014-04-29 · Modified
6.3EPSS 0.013
CVE-2014-3284
Cisco IOS XE on ASR1000 devices, when PPPoE termination is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed PPPoE packet, aka Bug ID CSCuo55180.
Published 2014-05-25 · Modified
6.1EPSS 0.012
CVE-2015-4243
The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.
Published 2015-07-08 · Modified
6.1EPSS 0.008
CVE-2012-1366
Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.
Published 2014-04-23 · Modified
6.1EPSS 0.007
CVE-2012-5723
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.
Published 2014-04-24 · Modified
6.1EPSS 0.007
CVE-2020-3503
Cisco IOS XE Software Guest Shell Unauthorized File System Access Vulnerability
Published 2020-09-24 · Modified
6.0EPSS 0.003
← Prev2 / 2