VendorsCiscoios_xe16.5.1a
Vulnerabilities

Cisco IOS Xe 16.5.1a

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

60CVEs
CVE-2017-12229
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software. The vulnerability is due to insufficient input validation for the REST API of the affected software. An attacker could exploit this vulnerability by sending a malicious API request to an affected device. A successful exploit could allow the attacker to bypass authentication and gain access to the web UI of the affected software. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuz46036.
Published 2017-09-28 · Modified
10.0EPSS 0.052
CVE-2020-3227
Cisco IOx for IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
10.0EPSS 0.034
CVE-2021-1619
Cisco IOS XE Software NETCONF and RESTCONF Authentication Bypass Vulnerability
Published 2021-09-23 · Modified
9.8EPSS 0.018
CVE-2024-20510
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server. An attacker could exploit this vulnerability by connecting to a wireless network that is configured for CWA and sending traffic through an affected device that should be denied by the configured ACL before user authentication. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device before the user authentication is completed, allowing the attacker to access trusted networks that the device might be protecting.
Published 2024-09-25 · Analyzed
9.3EPSS 0.003
CVE-2020-3229
Cisco IOS XE Software Web UI Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.053
CVE-2019-1755
Cisco IOS XE Software Command Injection Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.034
CVE-2020-3219
Cisco IOS XE Software Web UI Command Injection Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.033
CVE-2022-20719
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.027
CVE-2022-20718
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.024
CVE-2022-20723
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.021
CVE-2022-20720
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.015
CVE-2019-1743
Cisco IOS XE Software Arbitrary File Upload Vulnerability
Published 2019-03-27 · Modified
8.8EPSS 0.022
CVE-2020-3425
Cisco IOS XE Software Privilege Escalation Vulnerabilities
Published 2020-09-24 · Modified
8.8EPSS 0.018
CVE-2019-1745
Cisco IOS XE Software Command Injection Vulnerability
Published 2019-03-27 · Modified
8.8EPSS 0.004
CVE-2019-1737
Cisco IOS and IOS XE Software IP Service Level Agreement Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.026
CVE-2019-1739
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2019-1738
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2019-1740
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
Published 2019-03-27 · Modified
8.6EPSS 0.022
CVE-2021-1446
Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2020-3203
Cisco IOS XE Software Catalyst 9800 Series Wireless Controllers Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.008
CVE-2024-20314
A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain IPv4 packets. An attacker could exploit this vulnerability by sending certain IPv4 packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition.
Published 2024-03-27 · Analyzed
8.6EPSS 0.008
CVE-2023-20033
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when processing traffic that is received on the management interface. An attacker could exploit this vulnerability by sending a high rate of traffic to the management interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2024-20480
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover. This vulnerability is due to improper handling of IPv4 DHCP packets. An attacker could exploit this vulnerability by sending certain IPv4 DHCP packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition that requires a manual reload to recover.
Published 2024-09-25 · Analyzed
8.6EPSS 0.006
CVE-2025-20200
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20197
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20198
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20199
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2021-1442
Cisco IOS XE Software Plug-and-Play Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.8EPSS 0.002
CVE-2022-20692
Cisco IOS XE Software NETCONF Over SSH Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.7EPSS 0.011
CVE-2025-20174
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
Published 2025-02-05 · Analyzed
7.7EPSS 0.008
CVE-2022-20724
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.6EPSS 0.013
CVE-2019-1742
Cisco IOS XE Software Information Disclosure Vulnerability
Published 2019-03-27 · Modified
7.5EPSS 0.022
CVE-2024-20307
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerability by sending crafted UDP packets to an affected system. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Note: Only traffic that is directed to the affected system can be used to exploit this vulnerability. This vulnerability can be triggered by IPv4 and IPv6 traffic.
Published 2024-03-27 · Analyzed
7.5EPSS 0.007
CVE-2021-1403
Cisco IOS XE Software Web UI Cross-Site WebSocket Hijacking Vulnerability
Published 2021-03-24 · Modified
7.4EPSS 0.006
CVE-2021-1352
Cisco IOS XE Software DECnet Phase IV/OSI Denial of Service Vulnerability
Published 2021-03-24 · Modified
7.4EPSS 0.004
CVE-2025-20189
A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper memory management when Cisco IOS XE Software is processing Address Resolution Protocol (ARP) messages. An attacker could exploit this vulnerability by sending crafted ARP messages at a high rate over a period of time to an affected device. A successful exploit could allow the attacker to exhaust system resources, which eventually triggers a reload of the active route switch processor (RSP). If a redundant RSP is not present, the router reloads.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2025-20140
A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of IPv6 network requests from an associated wireless IPv6 client to an affected device. To associate a client to a device, an attacker may first need to authenticate to the network, or associate freely in the case of a configured open network. A successful exploit could allow the attacker to cause the wncd process to consume available memory and eventually cause the device to stop responding, resulting in a DoS condition.
Published 2025-05-07 · Analyzed
7.4EPSS 0.002
CVE-2023-20273
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inject commands to the underlying operating system with root privileges.
Published 2023-10-24 · Analyzed
7.2KEVEPSS 0.896
CVE-2022-20727
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.2EPSS 0.011
CVE-2020-3213
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
7.2EPSS 0.004
1 / 2Next →