VendorsCiscoios_xe16.10.1e
Vulnerabilities

Cisco IOS Xe 16.10.1e

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

93CVEs
CVE-2020-3227
Cisco IOx for IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
10.0EPSS 0.034
CVE-2021-34770
Cisco IOS XE Software for Catalyst 9000 Family Wireless Controllers CAPWAP Remote Code Execution Vulnerability
Published 2021-09-23 · Analyzed
10.0EPSS 0.030
CVE-2021-1619
Cisco IOS XE Software NETCONF and RESTCONF Authentication Bypass Vulnerability
Published 2021-09-23 · Modified
9.8EPSS 0.018
CVE-2026-20272
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.8EPSS 0.004
CVE-2024-20510
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server. An attacker could exploit this vulnerability by connecting to a wireless network that is configured for CWA and sending traffic through an affected device that should be denied by the configured ACL before user authentication. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device before the user authentication is completed, allowing the attacker to access trusted networks that the device might be protecting.
Published 2024-09-25 · Analyzed
9.3EPSS 0.003
CVE-2021-1435
Cisco IOS XE Software Web UI Command Injection Vulnerability
Published 2021-03-24 · Modified
9.0EPSS 0.081
CVE-2020-3229
Cisco IOS XE Software Web UI Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.053
CVE-2020-3218
Cisco IOS XE Software Web UI Remote Code Execution Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.049
CVE-2020-3211
Cisco IOS XE Software Web UI Command Injection Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.035
CVE-2020-3219
Cisco IOS XE Software Web UI Command Injection Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.033
CVE-2022-20719
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.027
CVE-2022-20718
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.024
CVE-2022-20723
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.021
CVE-2022-20720
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.015
CVE-2026-20267
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.0EPSS 0.003
CVE-2020-3425
Cisco IOS XE Software Privilege Escalation Vulnerabilities
Published 2020-09-24 · Modified
8.8EPSS 0.018
CVE-2020-3225
Cisco IOS and IOS XE Software Common Industrial Protocol Denial of Service Vulnerabilities
Published 2020-06-03 · Modified
8.6EPSS 0.021
CVE-2020-3226
Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.016
CVE-2020-3221
Cisco IOS XE Software Flexible NetFlow Version 9 Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.015
CVE-2022-20683
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Application Visibility and Control Denial of Service Vulnerability
Published 2022-04-15 · Modified
8.6EPSS 0.015
CVE-2021-1446
Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2021-1373
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2023-20027
Cisco IOS XE Software Virtual Fragmentation Reassembly Denial of Service Vulnerability
Published 2023-03-23 · Modified
8.6EPSS 0.010
CVE-2024-20436
A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.
Published 2024-09-25 · Analyzed
8.6EPSS 0.009
CVE-2020-3203
Cisco IOS XE Software Catalyst 9800 Series Wireless Controllers Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.008
CVE-2024-20314
A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain IPv4 packets. An attacker could exploit this vulnerability by sending certain IPv4 packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition.
Published 2024-03-27 · Analyzed
8.6EPSS 0.008
CVE-2023-20227
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2023-20187
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned out more than seven times on an affected device. An attacker could exploit this vulnerability by sending a specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packet through the affected device. A successful exploit could allow the attacker to cause a reload of the affected device, resulting in a DoS condition.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2024-20480
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover. This vulnerability is due to improper handling of IPv4 DHCP packets. An attacker could exploit this vulnerability by sending certain IPv4 DHCP packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition that requires a manual reload to recover.
Published 2024-09-25 · Analyzed
8.6EPSS 0.006
CVE-2026-20301
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
Published 2026-08-05 · Analyzed
8.6EPSS 0.003
CVE-2026-20269
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20270
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20268
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20273
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Analyzed
8.6EPSS 0.003
CVE-2026-20271
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2021-1443
Cisco IOS XE Software Web UI OS Command Injection Vulnerability
Published 2021-03-24 · Modified
8.5EPSS 0.023
CVE-2025-20200
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20197
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20199
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20198
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
1 / 3Next →