VendorsCiscoasr_9912any version
Vulnerabilities

Cisco ASR 9912 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2017-12240
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.
Published 2017-09-28 · Analyzed
10.0KEVEPSS 0.138
CVE-2020-3118
Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
Published 2020-02-05 · Analyzed
8.8KEVEPSS 0.117
CVE-2018-0167
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCuo17183, CSCvd73487.
Published 2018-03-28 · Analyzed
8.8KEVEPSS 0.034
CVE-2018-0418
A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a lack of input and validation checking on certain Precision Time Protocol (PTP) ingress traffic to an affected device. An attacker could exploit this vulnerability by injecting malformed traffic into an affected device. A successful exploit could allow the attacker to cause services on the device to become unresponsive, resulting in a DoS condition. Cisco Bug IDs: CSCvj22858.
Published 2018-08-15 · Modified
8.6EPSS 0.040
CVE-2020-3566
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
Published 2020-08-29 · Analyzed
8.6KEVEPSS 0.037
CVE-2020-3569
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities
Published 2020-09-23 · Analyzed
8.6KEVEPSS 0.033
CVE-2018-0136
A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect handling of IPv6 packets with a fragment header extension. An attacker could exploit this vulnerability by sending IPv6 packets designed to trigger the issue either to or through the Trident-based line card. A successful exploit could allow the attacker to trigger a reload of Trident-based line cards, resulting in a DoS during the period of time the line card takes to restart. This vulnerability affects Cisco Aggregation Services Router (ASR) 9000 Series when the following conditions are met: The router is running Cisco IOS XR Software Release 5.3.4, and the router has installed Trident-based line cards that have IPv6 configured. A software maintenance upgrade (SMU) has been made available that addresses this vulnerability. The fix has also been incorporated into service pack 7 for Cisco IOS XR Software Release 5.3.4. Cisco Bug IDs: CSCvg46800.
Published 2018-01-31 · Modified
8.6EPSS 0.027
CVE-2020-26070
Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers Slow Path Forwarding Denial of Service Vulnerability
Published 2020-11-12 · Modified
8.6EPSS 0.019
CVE-2019-1686
Cisco ASR 9000 Series Aggregation Services Routers ACL Bypass Vulnerability
Published 2019-04-17 · Modified
8.6EPSS 0.016
CVE-2019-16021
Cisco IOS XR Software BGP EVPN Denial of Service Vulnerabilities
Published 2020-09-23 · Modified
8.6EPSS 0.015
CVE-2019-16019
Cisco IOS XR Software BGP EVPN Denial of Service Vulnerabilities
Published 2020-09-23 · Modified
8.6EPSS 0.013
CVE-2019-16020
Cisco IOS XR Software BGP EVPN Denial of Service Vulnerabilities
Published 2020-01-26 · Modified
8.6EPSS 0.013
CVE-2019-16022
Cisco IOS XR Software BGP EVPN Denial of Service Vulnerabilities
Published 2020-01-26 · Modified
8.6EPSS 0.013
CVE-2019-15989
Cisco IOS XR Software Border Gateway Protocol Attribute Denial of Service Vulnerability
Published 2020-01-26 · Modified
8.6EPSS 0.013
CVE-2019-16023
Cisco IOS XR Software BGP EVPN Denial of Service Vulnerabilities
Published 2020-09-23 · Modified
8.6EPSS 0.013
CVE-2021-34720
Cisco IOS XR Software IP Service Level Agreements and Two-Way Active Measurement Protocol Denial of Service Vulnerability
Published 2021-09-09 · Modified
8.6EPSS 0.013
CVE-2022-20919
Cisco IOS and IOS XE Software Common Industrial Protocol Request Denial of Service Vulnerability
Published 2022-09-30 · Modified
8.6EPSS 0.011
CVE-2023-20049
Cisco IOS XR Software for ASR 9000 Series Routers Bidirectional Forwarding Detection Denial of Service Vulnerability
Published 2023-03-09 · Modified
8.6EPSS 0.010
CVE-2022-20848
Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points UDP Processing Denial of Service Vulnerability
Published 2022-09-30 · Modified
8.6EPSS 0.009
CVE-2025-20142
Cisco IOS XR Software for ASR 9000 Series Routers L2VPN Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
8.6EPSS 0.005
CVE-2025-20146
Cisco IOS XR Software for ASR 9000 Series Routers Layer 3 Multicast Routing Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
8.6EPSS 0.005
CVE-2021-34718
Cisco IOS XR Software Arbitrary File Read and Write Vulnerability
Published 2021-09-09 · Modified
8.5EPSS 0.016
CVE-2020-3530
Cisco IOS XR Authenticated User Privilege Escalation Vulnerability
Published 2020-09-04 · Modified
8.4EPSS 0.003
CVE-2017-12231
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.
Published 2017-09-28 · Analyzed
7.8KEVEPSS 0.071
CVE-2015-0695
Cisco IOS XR 4.3.4 through 5.3.0 on ASR 9000 devices, when uRPF, PBR, QoS, or an ACL is configured, does not properly handle bridge-group virtual interface (BVI) traffic, which allows remote attackers to cause a denial of service (chip and card hangs and reloads) by triggering use of a BVI interface for IPv4 packets, aka Bug ID CSCur62957.
Published 2015-04-17 · Modified
7.8EPSS 0.034
CVE-2021-34728
Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities
Published 2021-09-09 · Modified
7.8EPSS 0.003
CVE-2021-34719
Cisco IOS XR Software Authenticated User Privilege Escalation Vulnerabilities
Published 2021-09-09 · Modified
7.8EPSS 0.003
CVE-2023-20065
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Cisco IOx application container. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges.
Published 2023-03-23 · Modified
7.8EPSS 0.002
CVE-2023-20236
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the iPXE boot process on an affected device. A successful exploit could allow the attacker to boot an unverified software image on the affected device.
Published 2023-09-13 · Modified
7.8EPSS 0.001
CVE-2019-16027
Cisco IOS XR Software Intermediate System–to–Intermediate System Denial of Service Vulnerability
Published 2020-01-26 · Modified
7.7EPSS 0.015
CVE-2016-1407
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.
Published 2016-05-25 · Modified
7.5EPSS 0.018
CVE-2014-3396
Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.
Published 2014-10-05 · Modified
7.5EPSS 0.014
CVE-2021-34737
Cisco IOS XR Software DHCP Version 4 Server Denial of Service Vulnerability
Published 2021-09-09 · Modified
7.5EPSS 0.013
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2019-16018
Cisco IOS XR Software EVPN Operational Routes Denial of Service Vulnerability
Published 2020-01-26 · Modified
7.4EPSS 0.011
CVE-2018-0241
A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadcast packets that are forwarded to an IPv4 helper address. An attacker could exploit this vulnerability by sending multiple UDP broadcast packets to the affected device. An exploit could allow the attacker to cause a buffer leak on the affected device, eventually resulting in a DoS condition requiring manual intervention to recover. This vulnerability affects all Cisco IOS XR platforms running 6.3.1, 6.2.3, or earlier releases of Cisco IOS XR Software when at least one IPv4 helper address is configured on an interface of the device. Cisco Bug IDs: CSCvi35625.
Published 2018-04-19 · Modified
7.4EPSS 0.008
CVE-2019-1846
Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers MPLS OAM Denial of Service Vulnerability
Published 2019-05-16 · Modified
7.4EPSS 0.006
CVE-2021-34713
Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
Published 2021-09-09 · Modified
7.4EPSS 0.004
CVE-2024-20327
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of malformed PPPoE packets that are received on a router that is running Broadband Network Gateway (BNG) functionality with PPPoE termination on a Lightspeed-based or Lightspeed-Plus-based line card. An attacker could exploit this vulnerability by sending a crafted PPPoE packet to an affected line card interface that does not terminate PPPoE. A successful exploit could allow the attacker to crash the ppp_ma process, resulting in a DoS condition for PPPoE traffic across the router.
Published 2024-03-13 · Analyzed
7.4EPSS 0.003
CVE-2022-20677
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.2EPSS 0.006
1 / 2Next →