VendorsCiscoasr_9904all versions
Vulnerabilities

Cisco ASR 9904

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2019-12709
Cisco IOS XR Software for Cisco ASR 9000 VMAN CLI Privilege Escalation Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.005
CVE-2021-34722
Cisco IOS XR Software Command Injection Vulnerabilities
Published 2021-09-09 · Modified
7.2EPSS 0.003
CVE-2014-2176
Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928.
Published 2014-06-14 · Modified
7.1EPSS 0.028
CVE-2021-34721
Cisco IOS XR Software Command Injection Vulnerabilities
Published 2021-09-09 · Modified
6.9EPSS 0.003
CVE-2018-15428
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2018-10-05 · Modified
6.8EPSS 0.020
CVE-2019-1909
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2019-07-06 · Modified
6.8EPSS 0.015
CVE-2023-20066
Cisco IOS XE Software Web UI Path Traversal Vulnerability
Published 2023-03-23 · Modified
6.5EPSS 0.017
CVE-2014-3308
Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.
Published 2014-07-07 · Modified
6.4EPSS 0.028
CVE-2014-3322
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.
Published 2014-07-24 · Modified
6.1EPSS 0.012
CVE-2022-20849
Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.003
CVE-2015-4205
Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.
Published 2015-06-23 · Modified
5.7EPSS 0.009
CVE-2014-3321
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
Published 2014-07-18 · Modified
5.7EPSS 0.006
CVE-2019-1842
Cisco IOS XR Software Secure Shell Authentication Vulnerability
Published 2019-06-05 · Modified
5.5EPSS 0.012
CVE-2019-15998
Cisco IOS XR Software NETCONF Over Secure Shell ACL Bypass Vulnerability
Published 2019-11-26 · Modified
5.3EPSS 0.007
CVE-2015-6297
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.
Published 2015-09-18 · Modified
5.0EPSS 0.024
CVE-2015-6301
The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.
Published 2015-09-20 · Modified
5.0EPSS 0.024
CVE-2015-4284
The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670.
Published 2015-07-22 · Modified
5.0EPSS 0.024
CVE-2015-0672
The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.
Published 2015-03-26 · Modified
5.0EPSS 0.017
CVE-2015-0694
Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
Published 2015-04-11 · Modified
5.0EPSS 0.016
CVE-2014-3335
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
Published 2014-08-26 · Modified
4.6EPSS 0.011
CVE-2023-20064
Cisco IOS XR Software Bootloader Unauthenticated Information Disclosure Vulnerability
Published 2023-03-09 · Modified
4.6EPSS 0.003
← Prev2 / 2