VendorsCiscoios_xeall versions
Vulnerabilities

Cisco IOS Xe

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

519CVEs
CVE-2020-3214
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.004
CVE-2020-3215
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.004
CVE-2021-1390
Cisco IOS XE Software Local Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.003
CVE-2020-3396
Cisco IOS XE Software IOx Guest Shell USB SSD Namespace Protection Privilege Escalation Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.003
CVE-2021-1441
Cisco IOS XE Software Hardware Initialization Routines Arbitrary Code Execution Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.003
CVE-2021-1391
Cisco IOS and IOS XE Software Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.003
CVE-2019-12662
Cisco NX-OS and IOS XE Software Virtual Service Image Signature Bypass Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.003
CVE-2022-20676
Cisco IOS XE Software Tool Command Language Privilege Escalation Vulnerability
Published 2022-04-15 · Modified
7.2EPSS 0.003
CVE-2021-1454
Cisco IOS XE SD-WAN Software Parameter Injection Vulnerabilities
Published 2021-03-24 · Modified
7.2EPSS 0.003
CVE-2020-3209
Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.003
CVE-2019-12649
Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.002
CVE-2018-15374
Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
Published 2018-10-05 · Modified
7.2EPSS 0.002
CVE-2021-1375
Cisco IOS XE Software Fast Reload Vulnerabilities
Published 2021-03-24 · Modified
7.2EPSS 0.002
CVE-2021-1376
Cisco IOS XE Software Fast Reload Vulnerabilities
Published 2021-03-24 · Modified
7.2EPSS 0.002
CVE-2021-1453
Cisco IOS XE Software for the Catalyst 9000 Family Arbitrary Code Execution Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.002
CVE-2018-0476
Cisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.1EPSS 0.137
CVE-2017-12319
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.
Published 2018-03-27 · Analyzed
7.1KEVEPSS 0.052
CVE-2018-0469
Cisco IOS XE Software Web UI Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.1EPSS 0.031
CVE-2016-1344
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
Published 2016-03-26 · Modified
7.1EPSS 0.030
CVE-2017-3850
A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4 through 15.6) and Cisco IOS XE Software (3.7 through 3.18, and 16) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted IPv6 packet to a device that is running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature. A device must meet two conditions to be affected by this vulnerability: (1) the device must be running a version of Cisco IOS Software or Cisco IOS XE Software that supports ANI (regardless of whether ANI is configured); and (2) the device must have a reachable IPv6 interface. An exploit could allow the attacker to cause the affected device to reload. Cisco Bug IDs: CSCvc42729.
Published 2017-03-21 · Modified
7.1EPSS 0.025
CVE-2009-1168
Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (memory corruption and device reload) by using an RFC4271 peer to send an update with a long series of AS numbers, aka Bug ID CSCsy86021.
Published 2009-07-30 · Modified
7.1EPSS 0.025
CVE-2015-0681
The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15.0(2)ED1, 15.0(2)EY3, 15.1(3)SVF4a, and 15.2(2)JB1 and IOS XE 2.5.x, 2.6.x, 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, and 3.5.xS before 3.6.0S; 3.1.xSG, 3.2.xSG, and 3.3.xSG before 3.4.0SG; 3.2.xSE before 3.3.0SE; 3.2.xXO before 3.3.0XO; 3.2.xSQ; 3.3.xSQ; and 3.4.xSQ allows remote attackers to cause a denial of service (device hang or reload) via multiple requests that trigger improper memory management, aka Bug ID CSCts66733.
Published 2015-07-24 · Modified
7.1EPSS 0.023
CVE-2012-4617
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
Published 2012-09-27 · Modified
7.1EPSS 0.023
CVE-2019-1760
Cisco IOS XE Software Performance Routing Version 3 Denial of Service Vulnerability
Published 2019-03-28 · Modified
7.1EPSS 0.021
CVE-2018-0282
Cisco IOS and IOS XE Software TCP Denial of Service Vulnerability
Published 2019-01-10 · Modified
7.1EPSS 0.020
CVE-2013-1167
Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled during the processing of encapsulation, aka Bug ID CSCtt11558.
Published 2013-04-11 · Modified
7.1EPSS 0.020
CVE-2013-5472
The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.
Published 2013-09-27 · Modified
7.1EPSS 0.017
CVE-2015-0688
Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.
Published 2015-04-04 · Modified
7.1EPSS 0.017
CVE-2010-2830
The IGMPv3 implementation in Cisco IOS 12.2, 12.3, 12.4, and 15.0 and IOS XE 2.5.x before 2.5.2, when PIM is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed IGMP packet, aka Bug ID CSCte14603.
Published 2010-09-23 · Modified
7.1EPSS 0.016
CVE-2012-4622
Cisco IOS XE 03.02.00.XO.15.0(2)XO on Catalyst 4500E series switches, when a Supervisor Engine 7L-E card is installed, allows remote attackers to cause a denial of service (card reload) via malformed packets that trigger uncorrected ECC error messages, aka Bug ID CSCty88456.
Published 2012-09-27 · Modified
7.1EPSS 0.015
CVE-2013-1143
The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory access and device reload) via a traffic engineering PATH message in an RSVP packet, aka Bug ID CSCtg39957.
Published 2013-03-28 · Modified
7.1EPSS 0.014
CVE-2013-6704
Cisco IOS XE does not properly manage memory for TFTP UDP flows, which allows remote attackers to cause a denial of service (memory consumption) via TFTP (1) client or (2) server traffic, aka Bug IDs CSCuh09324 and CSCty42686.
Published 2013-12-03 · Modified
7.1EPSS 0.013
CVE-2022-20694
Cisco IOS XE Software Border Gateway Protocol Resource Public Key Infrastructure Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.1EPSS 0.012
CVE-2018-0189
A vulnerability in the Forwarding Information Base (FIB) code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, network attacker to cause a denial of service (DoS) condition. The vulnerability is due to a limitation in the way the FIB is internally representing recursive routes. An attacker could exploit this vulnerability by injecting routes into the routing protocol that have a specific recursive pattern. The attacker must be in a position on the network that provides the ability to inject a number of recursive routes with a specific pattern. An exploit could allow the attacker to cause an affected device to reload, creating a DoS condition. Cisco Bug IDs: CSCva91655.
Published 2018-03-28 · Modified
7.1EPSS 0.010
CVE-2020-3220
Cisco IOS XE Software IPsec VPN Denial of Service Vulnerability
Published 2020-06-03 · Modified
7.1EPSS 0.005
CVE-2017-6606
A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More Information: CSCuz06639 CSCuz42122. Known Affected Releases: 15.6(1.1)S 16.1.2 16.2.0 15.2(1)E. Known Fixed Releases: Denali-16.1.3 16.2(1.8) 16.1(2.61) 15.6(2)SP 15.6(2)S1 15.6(1)S2 15.5(3)S3a 15.5(3)S3 15.5(2)S4 15.5(1)S4 15.4(3)S6a 15.4(3)S6 15.3(3)S8a 15.3(3)S8 15.2(5)E 15.2(4)E3 15.2(3)E5 15.0(2)SQD3 15.0(1.9.2)SQD3 3.9(0)E.
Published 2017-04-07 · Modified
6.9EPSS 0.005
CVE-2021-1398
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Published 2021-03-24 · Modified
6.9EPSS 0.004
CVE-2020-3416
Cisco IOS XE Software for Cisco ASR 900 Series Route Switch Processor 3 Arbitrary Code Execution Vulnerabilities
Published 2020-09-24 · Modified
6.9EPSS 0.003
CVE-2020-3513
Cisco IOS XE Software for Cisco ASR 900 Series Route Switch Processor 3 Arbitrary Code Execution Vulnerabilities
Published 2020-09-24 · Modified
6.9EPSS 0.003
CVE-2021-1281
Cisco IOS XE SD-WAN Software Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
6.9EPSS 0.003
← Prev10 / 13Next →