VendorsCiscoios_xeall versions
Vulnerabilities

Cisco IOS Xe

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

519CVEs
CVE-2020-3428
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WLAN Local Profiling Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2020-3511
Cisco IOS and IOS XE Software ISDN Q.931 Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2020-3494
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2020-3508
Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2020-3512
Cisco IOS and IOS XE Software PROFINET Link Layer Discovery Protocol Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2021-1352
Cisco IOS XE Software DECnet Phase IV/OSI Denial of Service Vulnerability
Published 2021-03-24 · Modified
7.4EPSS 0.004
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2021-1621
Cisco IOS XE Software Interface Queue Wedge Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2024-20303
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper management of mDNS client entries. An attacker could exploit this vulnerability by connecting to the wireless network and sending a continuous stream of specific mDNS packets. A successful exploit could allow the attacker to cause the wireless controller to have high CPU utilization, which could lead to access points (APs) losing their connection to the controller and result in a DoS condition.
Published 2024-03-27 · Analyzed
7.4EPSS 0.003
CVE-2023-20067
Cisco IOS XE Software for Wireless LAN Controllers HTTP Client Profiling Denial of Service Vulnerability
Published 2023-03-23 · Modified
7.4EPSS 0.003
CVE-2022-20915
Cisco IOS XE Software IPv6 VPN over MPLS Denial of Service Vulnerability
Published 2022-10-10 · Modified
7.4EPSS 0.003
CVE-2024-20354
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit this vulnerability by connecting as a wireless client to an affected AP and sending specific malformed frames over the wireless connection. A successful exploit could allow the attacker to cause degradation of service to other clients, which could potentially lead to a complete DoS condition.
Published 2024-03-27 · Analyzed
7.4EPSS 0.003
CVE-2024-20313
A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by a device. An attacker could exploit this vulnerability by sending a malformed OSPF update to the device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Published 2024-04-24 · Modified
7.4EPSS 0.003
CVE-2025-20189
A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (ARP) messages. An attacker could exploit this vulnerability by sending crafted ARP messages at a high rate over a period of time to an affected device. A successful exploit could allow the attacker to exhaust system resources, which eventually triggers a reload of the active route switch processor (RSP). If a redundant RSP is not present, the router reloads.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2025-20140
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2025-20202
A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighbor reports when they are processed by the wireless controller. An attacker could exploit this vulnerability by sending a crafted CDP packet to an AP. A successful exploit could allow the attacker to cause an unexpected reload of the wireless controller that is managing the AP, resulting in a DoS condition that affects the wireless network.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2025-20311
A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to improper handling of crafted Ethernet frames. An attacker could exploit this vulnerability by sending crafted Ethernet frames through an affected switch. A successful exploit could allow the attacker to cause the egress port to which the crafted frame is forwarded to start dropping all frames, resulting in a denial of service (DoS) condition.
Published 2025-09-24 · Analyzed
7.4EPSS 0.002
CVE-2021-1432
Cisco IOS XE SD-WAN Software Arbitrary Command Execution Vulnerability
Published 2021-03-24 · Modified
7.3EPSS 0.003
CVE-2023-20273
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Published 2023-10-24 · Analyzed
7.2KEVEPSS 0.896
CVE-2019-12666
Cisco IOS XE Software Path Traversal Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.011
CVE-2022-20727
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.2EPSS 0.011
CVE-2022-20851
Cisco IOS XE Software Web UI Command Injection Vulnerability
Published 2022-09-30 · Modified
7.2EPSS 0.010
CVE-2021-1382
Cisco IOS XE SD-WAN Software Command Injection Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.007
CVE-2019-1649
Cisco Secure Boot Hardware Tampering Vulnerability
Published 2019-05-13 · Modified
7.2EPSS 0.006
CVE-2020-3207
Cisco IOS XE Software Command Injection Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.006
CVE-2021-1383
Cisco IOS XE SD-WAN Software Parameter Injection Vulnerabilities
Published 2021-03-24 · Modified
7.2EPSS 0.006
CVE-2018-0477
Cisco IOS XE Software Command Injection Vulnerabilities
Published 2018-10-05 · Modified
7.2EPSS 0.005
CVE-2018-0481
Cisco IOS XE Software Command Injection Vulnerabilities
Published 2018-10-05 · Modified
7.2EPSS 0.005
CVE-2019-12661
Cisco IOS XE Software Virtualization Manager CLI Command Injection Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.004
CVE-2017-6796
A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the platform usb modem command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the platform usb modem command in the CLI of an affected device. A successful exploit could allow the attacker to inject and execute arbitrary commands on the underlying operating system of an affected device. Cisco Bug IDs: CSCve48949.
Published 2017-09-07 · Modified
7.2EPSS 0.004
CVE-2017-12239
A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system. The vulnerability exists because an engineering console port is available on the motherboard of the affected line cards. An attacker could exploit this vulnerability by physically connecting to the console port on the line card. A successful exploit could allow the attacker to gain full access to the affected device's operating system. This vulnerability affects only Cisco ASR 1000 Series Routers that have removable line cards and Cisco cBR-8 Converged Broadband Routers, if they are running certain Cisco IOS XE 3.16 through 16.5 releases. Cisco Bug IDs: CSCvc65866, CSCve77132.
Published 2017-09-28 · Modified
7.2EPSS 0.004
CVE-2020-3213
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.004
CVE-2018-0183
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability is due to the affected software improperly sanitizing command arguments to prevent access to internal data structures on a device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit this vulnerability on the device by executing CLI commands that contain crafted arguments. A successful exploit could allow the attacker to gain access to the underlying Linux shell of the affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCuv91356.
Published 2018-03-28 · Modified
7.2EPSS 0.004
CVE-2018-0184
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability is due to the affected software improperly sanitizing command arguments to prevent access to internal data structures on a device. An attacker who has privileged EXEC mode (privilege level 15) access to an affected device could exploit this vulnerability on the device by executing CLI commands that contain crafted arguments. A successful exploit could allow the attacker to gain access to the underlying Linux shell of the affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCve74432.
Published 2018-03-28 · Modified
7.2EPSS 0.004
CVE-2018-15371
Cisco IOS XE Software Shell Access Authentication Bypass Vulnerability
Published 2018-10-05 · Modified
7.2EPSS 0.004
CVE-2018-15368
Cisco IOS XE Software Privileged EXEC Mode Root Shell Access Vulnerability
Published 2018-10-05 · Modified
7.2EPSS 0.004
CVE-2020-3423
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.004
CVE-2015-6383
Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130.
Published 2015-12-03 · Modified
7.2EPSS 0.004
CVE-2020-3417
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.004
CVE-2021-34729
Cisco IOS XE SD-WAN Software Command Injection Vulnerability
Published 2021-09-23 · Modified
7.2EPSS 0.004
← Prev9 / 13Next →