VendorsCiscoios_xeall versions
Vulnerabilities

Cisco IOS Xe

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

519CVEs
CVE-2022-20679
Cisco IOS XE Software IPSec Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.7EPSS 0.013
CVE-2022-20692
Cisco IOS XE Software NETCONF Over SSH Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.7EPSS 0.011
CVE-2021-1623
Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers Simple Network Management Protocol Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.7EPSS 0.011
CVE-2020-3232
Cisco ASR 920 Series Aggregation Services Router Model 12SZ-IM SNMP Denial of Service Vulnerability
Published 2020-06-03 · Modified
7.7EPSS 0.010
CVE-2025-20174
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
Published 2025-02-05 · Analyzed
7.7EPSS 0.008
CVE-2026-20124
Cisco IOS XE Software SNMP Denial of Service Vulnerability
Published 2026-08-05 · Analyzed
7.7EPSS 0.005
CVE-2025-20312
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.
Published 2025-09-24 · Undergoing Analysis
7.7EPSS 0.004
CVE-2022-20724
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.6EPSS 0.013
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2016-6415
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.
Published 2016-09-19 · Analyzed
7.5KEV1 PoCEPSS 0.877
CVE-2017-6627
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP packets with a destination port of 0 to an affected device. A successful exploit could allow the attacker to cause UDP packets to be held in the input interfaces queue, resulting in a DoS condition. The input interface queue will stop holding UDP packets when it receives 250 packets. Cisco Bug IDs: CSCup10024, CSCva55744, CSCva95506.
Published 2017-09-07 · Analyzed
7.5KEVEPSS 0.062
CVE-2016-6393
The AAA service in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.1 through 3.18 and 16.2 allows remote attackers to cause a denial of service (device reload) via a failed SSH connection attempt that is mishandled during generation of an error-log message, aka Bug ID CSCuy87667.
Published 2016-10-05 · Modified
7.5EPSS 0.046
CVE-2016-1384
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
Published 2016-04-20 · Modified
7.5EPSS 0.025
CVE-2019-1742
Cisco IOS XE Software Information Disclosure Vulnerability
Published 2019-03-27 · Modified
7.5EPSS 0.022
CVE-2021-1223
Multiple Cisco Products Snort HTTP Detection Engine File Policy Bypass Vulnerability
Published 2021-01-13 · Modified
7.5EPSS 0.020
CVE-2019-12659
Cisco IOS XE Software HTTP Server Denial of Service Vulnerability
Published 2019-09-25 · Modified
7.5EPSS 0.018
CVE-2020-3444
Cisco SD-WAN Software Packet Filtering Bypass Vulnerability
Published 2020-11-06 · Modified
7.5EPSS 0.015
CVE-2019-12664
Cisco IOS XE Software ISDN Data Leak Vulnerability
Published 2019-09-25 · Modified
7.5EPSS 0.014
CVE-2017-6664
A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked. This vulnerability affected devices that are running Release 16.x of Cisco IOS XE Software and are configured to use Autonomic Networking. This vulnerability does not affect devices that are running an earlier release of Cisco IOS XE Software or devices that are not configured to use Autonomic Networking. More Information: CSCvd22328. Known Affected Releases: 15.5(1)S3.1 Denali-16.2.1.
Published 2017-08-07 · Modified
7.5EPSS 0.009
CVE-2024-20307
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerability by sending crafted UDP packets to an affected system. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: Only traffic that is directed to the affected system can be used to exploit this vulnerability. This vulnerability can be triggered by IPv4 and IPv6 traffic.
Published 2024-03-27 · Analyzed
7.5EPSS 0.007
CVE-2018-0475
Cisco IOS and IOS XE Software Cluster Management Protocol Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.4EPSS 0.009
CVE-2018-0471
Cisco IOS XE Software Cisco Discovery Protocol Memory Leak Vulnerability
Published 2018-10-05 · Modified
7.4EPSS 0.008
CVE-2021-34767
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers IPv6 Denial of Service Vulnerability
Published 2021-09-23 · Analyzed
7.4EPSS 0.008
CVE-2017-3849
A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS XE Software (possibly 3.7 through 3.18, and 16) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certain crafted packets. An attacker could exploit this vulnerability by sending a crafted autonomic network channel discovery packet to a device that has all the following characteristics: (1) running a Cisco IOS Software or Cisco IOS XE Software release that supports the ANI feature; (2) configured as an autonomic registrar; (3) has a whitelist configured. An exploit could allow the attacker to cause the affected device to reload. Note: Autonomic networking should be configured with a whitelist. Do not remove the whitelist as a workaround. Cisco Bug IDs: CSCvc42717.
Published 2017-03-21 · Modified
7.4EPSS 0.008
CVE-2020-3429
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WPA Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.007
CVE-2019-1750
Cisco IOS XE Software Catalyst 4500 Cisco Discovery Protocol Denial of Service Vulnerability
Published 2019-03-27 · Modified
7.4EPSS 0.007
CVE-2018-0165
A vulnerability in the Internet Group Management Protocol (IGMP) packet-processing functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust buffers on an affected device, resulting in a denial of service (DoS) condition, aka a Memory Leak. The vulnerability is due to the affected software insufficiently processing IGMP Membership Query packets that are sent to an affected device. An attacker could exploit this vulnerability by sending a large number of IGMP Membership Query packets, which contain certain values, to an affected device. A successful exploit could allow the attacker to exhaust buffers on the affected device, resulting in a DoS condition that requires the device to be reloaded manually. This vulnerability affects: Cisco Catalyst 4500 Switches with Supervisor Engine 8-E, if they are running Cisco IOS XE Software Release 3.x.x.E and IP multicast routing is configured; Cisco devices that are running Cisco IOS XE Software Release 16.x, if IP multicast routing is configured. Cisco Bug IDs: CSCuw09295, CSCve94496.
Published 2018-03-28 · Modified
7.4EPSS 0.007
CVE-2020-3465
Cisco IOS XE Software Ethernet Frame Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.007
CVE-2018-15373
Cisco IOS and IOS XE Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2018-10-05 · Modified
7.4EPSS 0.007
CVE-2020-3390
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Trap Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.006
CVE-2019-1749
Cisco Aggregation Services Router 900 Route Switch Processor 3 OSPFv2 Denial of Service Vulnerability
Published 2019-03-27 · Modified
7.4EPSS 0.006
CVE-2021-1403
Cisco IOS XE Software Web UI Cross-Site WebSocket Hijacking Vulnerability
Published 2021-03-24 · Modified
7.4EPSS 0.006
CVE-2020-3486
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.006
CVE-2020-3409
Cisco IOS and IOS XE Software PROFINET Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2022-20684
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Trap Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.4EPSS 0.005
CVE-2020-3488
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2020-3489
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2020-3493
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2020-3497
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2020-3487
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.005
← Prev8 / 13Next →