VendorsCiscoios_xe16.10.1s
Vulnerabilities

Cisco IOS Xe 16.10.1s

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

90CVEs
CVE-2021-1442
Cisco IOS XE Software Plug-and-Play Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.8EPSS 0.002
CVE-2025-20352
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP.
Published 2025-09-24 · Analyzed
7.7KEVEPSS 0.394
CVE-2022-20679
Cisco IOS XE Software IPSec Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.7EPSS 0.013
CVE-2022-20692
Cisco IOS XE Software NETCONF Over SSH Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.7EPSS 0.011
CVE-2025-20174
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
Published 2025-02-05 · Analyzed
7.7EPSS 0.008
CVE-2026-20124
Cisco IOS XE Software SNMP Denial of Service Vulnerability
Published 2026-08-05 · Analyzed
7.7EPSS 0.005
CVE-2022-20724
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.6EPSS 0.013
CVE-2024-20307
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerability by sending crafted UDP packets to an affected system. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: Only traffic that is directed to the affected system can be used to exploit this vulnerability. This vulnerability can be triggered by IPv4 and IPv6 traffic.
Published 2024-03-27 · Analyzed
7.5EPSS 0.007
CVE-2021-34767
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers IPv6 Denial of Service Vulnerability
Published 2021-09-23 · Analyzed
7.4EPSS 0.008
CVE-2021-1403
Cisco IOS XE Software Web UI Cross-Site WebSocket Hijacking Vulnerability
Published 2021-03-24 · Modified
7.4EPSS 0.006
CVE-2022-20684
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Trap Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.4EPSS 0.005
CVE-2021-1352
Cisco IOS XE Software DECnet Phase IV/OSI Denial of Service Vulnerability
Published 2021-03-24 · Modified
7.4EPSS 0.004
CVE-2023-20067
Cisco IOS XE Software for Wireless LAN Controllers HTTP Client Profiling Denial of Service Vulnerability
Published 2023-03-23 · Modified
7.4EPSS 0.003
CVE-2025-20140
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2025-20189
A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (ARP) messages. An attacker could exploit this vulnerability by sending crafted ARP messages at a high rate over a period of time to an affected device. A successful exploit could allow the attacker to exhaust system resources, which eventually triggers a reload of the active route switch processor (RSP). If a redundant RSP is not present, the router reloads.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2025-20202
A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighbor reports when they are processed by the wireless controller. An attacker could exploit this vulnerability by sending a crafted CDP packet to an AP. A successful exploit could allow the attacker to cause an unexpected reload of the wireless controller that is managing the AP, resulting in a DoS condition that affects the wireless network.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2025-20311
A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to improper handling of crafted Ethernet frames. An attacker could exploit this vulnerability by sending crafted Ethernet frames through an affected switch. A successful exploit could allow the attacker to cause the egress port to which the crafted frame is forwarded to start dropping all frames, resulting in a denial of service (DoS) condition.
Published 2025-09-24 · Analyzed
7.4EPSS 0.002
CVE-2023-20273
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Published 2023-10-24 · Analyzed
7.2KEVEPSS 0.896
CVE-2022-20727
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.2EPSS 0.011
CVE-2020-3207
Cisco IOS XE Software Command Injection Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.006
CVE-2021-1383
Cisco IOS XE SD-WAN Software Parameter Injection Vulnerabilities
Published 2021-03-24 · Modified
7.2EPSS 0.006
CVE-2020-3213
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.004
CVE-2020-3417
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.004
CVE-2020-3215
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.004
CVE-2021-1390
Cisco IOS XE Software Local Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.003
CVE-2021-1391
Cisco IOS and IOS XE Software Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.003
CVE-2020-3209
Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.003
CVE-2021-1375
Cisco IOS XE Software Fast Reload Vulnerabilities
Published 2021-03-24 · Modified
7.2EPSS 0.002
CVE-2021-1376
Cisco IOS XE Software Fast Reload Vulnerabilities
Published 2021-03-24 · Modified
7.2EPSS 0.002
CVE-2021-1453
Cisco IOS XE Software for the Catalyst 9000 Family Arbitrary Code Execution Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.002
CVE-2022-20694
Cisco IOS XE Software Border Gateway Protocol Resource Public Key Infrastructure Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.1EPSS 0.012
CVE-2020-3220
Cisco IOS XE Software IPsec VPN Denial of Service Vulnerability
Published 2020-06-03 · Modified
7.1EPSS 0.005
CVE-2021-1398
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Published 2021-03-24 · Modified
6.9EPSS 0.004
CVE-2021-1281
Cisco IOS XE SD-WAN Software Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
6.9EPSS 0.003
CVE-2022-20721
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
6.8EPSS 0.013
CVE-2022-20722
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
6.8EPSS 0.013
CVE-2025-20201
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
6.7EPSS 0.002
CVE-2025-20338
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by logging in to the device CLI with valid administrative (level 15) credentials and using crafted commands at the CLI prompt. A successful exploit could allow the attacker to execute arbitrary commands as root.
Published 2025-09-24 · Analyzed
6.7EPSS 0.002
CVE-2024-20414
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could exploit this vulnerability by persuading a currently authenticated administrator to follow a crafted link. A successful exploit could allow the attacker to change the configuration of the affected device.
Published 2024-09-25 · Analyzed
6.5EPSS 0.003
CVE-2021-1377
Cisco IOS and IOS XE Software ARP Resource Management Exhaustion Denial of Service Vulnerability
Published 2021-03-24 · Modified
5.8EPSS 0.014
← Prev2 / 3Next →