VendorsCiscoios_xeall versions
Vulnerabilities

Cisco IOS Xe

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

519CVEs
CVE-2017-3860
Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafted EnergyWise packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted EnergyWise packets to be processed by an affected device. An exploit could allow the attacker to cause a buffer overflow condition or a reload of the affected device, leading to a DoS condition. Cisco IOS Software and Cisco IOS XE Software support EnergyWise for IPv4 communication. Only IPv4 packets destined to a device configured as an EnergyWise domain member can trigger these vulnerabilities. IPv6 packets cannot be used to trigger these vulnerabilities. Cisco Bug ID CSCur29331.
Published 2017-04-20 · Modified
8.6EPSS 0.028
CVE-2019-1741
Cisco IOS XE Software Encrypted Traffic Analytics Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.028
CVE-2017-3864
A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during the parsing of a crafted DHCP packet. An attacker could exploit this vulnerability by sending crafted DHCP packets to an affected device that is configured as a DHCP client. A successful exploit could allow the attacker to cause a reload of an affected device, resulting in a DoS condition. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS or IOS XE Software and using a specific DHCP client configuration. Cisco Bug IDs: CSCuu43892.
Published 2017-03-22 · Modified
8.6EPSS 0.027
CVE-2018-0157
A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exploit this vulnerability by sending fragmented IP Version 4 or IP Version 6 packets through an affected device. An exploit could allow the attacker to cause the device to crash, resulting in a denial of service (DoS) condition. The following releases of Cisco IOS XE Software are vulnerable: Everest-16.4.1, Everest-16.4.2, Everest-16.5.1, Everest-16.5.1b, Everest-16.6.1, Everest-16.6.1a. Cisco Bug IDs: CSCvf60296.
Published 2018-03-28 · Modified
8.6EPSS 0.027
CVE-2019-1737
Cisco IOS and IOS XE Software IP Service Level Agreement Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.026
CVE-2019-1739
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2019-1752
Cisco IOS and IOS XE Software ISDN Interface Denial of Service Vulnerability
Published 2019-03-28 · Modified
8.6EPSS 0.025
CVE-2019-1738
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2019-1747
Cisco IOS and IOS XE Software Short Message Service Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.024
CVE-2019-1740
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
Published 2019-03-27 · Modified
8.6EPSS 0.022
CVE-2020-3225
Cisco IOS and IOS XE Software Common Industrial Protocol Denial of Service Vulnerabilities
Published 2020-06-03 · Modified
8.6EPSS 0.021
CVE-2019-12654
Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12653
Cisco IOS XE Software Raw Socket Transport Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12647
Cisco IOS and IOS XE Software IP Ident Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12657
Cisco IOS XE Software Unified Threat Defense Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12646
Cisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12658
Cisco IOS XE Software Filesystem Exhaustion Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2020-3421
Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
8.6EPSS 0.019
CVE-2020-3414
Cisco IOS XE Software for Cisco 4461 Integrated Services Routers Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.019
CVE-2018-0164
A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an interface queue wedge. The vulnerability is due to incorrect handling of crafted IPv6 packets. An attacker could exploit this vulnerability by sending crafted IPv6 packets through the device. An exploit could allow the attacker to cause an interface queue wedge. This vulnerability affects the Cisco cBR-8 Converged Broadband Router, Cisco ASR 1000 Series Aggregation Services Routers, and Cisco Cloud Services Router 1000V Series when configured with IPv6. In the field and internal testing, this vulnerability was only observed or reproduced on the Cisco cBR-8 Converged Broadband Router. The Cisco ASR 1000 Series Aggregation Services Routers and Cisco Cloud Services Router 1000V Series contain the same code logic, so affected trains have had the code fix applied; however, on these two products, the vulnerability has not been observed in the field or successfully reproduced internally. Cisco Bug IDs: CSCvd75185.
Published 2018-03-28 · Modified
8.6EPSS 0.018
CVE-2020-3228
Cisco IOS, IOS XE, and NX-OS Software Security Group Tag Exchange Protocol Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.018
CVE-2019-12663
Cisco IOS XE Software TrustSec Protected Access Credential Provisioning Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.018
CVE-2020-3226
Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.016
CVE-2020-3408
Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.016
CVE-2020-3407
Cisco IOS XE Software RESTCONF and NETCONF-YANG Access Control List Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.015
CVE-2020-3221
Cisco IOS XE Software Flexible NetFlow Version 9 Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.015
CVE-2020-3359
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Multicast DNS Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.015
CVE-2022-20683
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Application Visibility and Control Denial of Service Vulnerability
Published 2022-04-15 · Modified
8.6EPSS 0.015
CVE-2021-1446
Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2021-1373
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2020-3509
Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers DHCP Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2020-3480
Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2021-34768
Cisco IOS XE Software for Catalyst 9000 Family Wireless Controllers CAPWAP Denial of Service Vulnerabilities
Published 2021-09-23 · Modified
8.6EPSS 0.014
CVE-2021-34769
Cisco IOS XE Software for Catalyst 9000 Family Wireless Controllers CAPWAP Denial of Service Vulnerabilities
Published 2021-09-23 · Modified
8.6EPSS 0.014
CVE-2020-3510
Cisco IOS XE Software for Catalyst 9200 Series Switches Umbrella Connector Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2020-3492
Cisco IOS XE Software for Catalyst 9800 Series and Cisco AireOS Software for Cisco WLC Flexible NetFlow Version 9 Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2020-3527
Cisco Catalyst 9200 Series Switches Jumbo Frame Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2020-3526
Cisco IOS XE Software Common Open Policy Service Engine Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2020-3399
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2022-20682
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
Published 2022-04-15 · Modified
8.6EPSS 0.013
← Prev3 / 13Next →