VendorsCiscoios_xe16.8.1
Vulnerabilities

Cisco IOS Xe 16.8.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

96CVEs
CVE-2020-3227
Cisco IOx for IOS XE Software Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
10.0EPSS 0.034
CVE-2018-0315
A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect memory operations that the affected software performs when the software parses a username during login authentication. An attacker could exploit this vulnerability by attempting to authenticate to an affected device. A successful exploit could allow the attacker to execute arbitrary code on the affected device or cause the affected device to reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are running Cisco IOS XE Software Release Fuji 16.7.1 or Fuji 16.8.1 and are configured to use AAA for login authentication. Cisco Bug IDs: CSCvi25380.
Published 2018-06-07 · Modified
9.8EPSS 0.078
CVE-2021-1619
Cisco IOS XE Software NETCONF and RESTCONF Authentication Bypass Vulnerability
Published 2021-09-23 · Modified
9.8EPSS 0.018
CVE-2026-20272
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.8EPSS 0.004
CVE-2024-20510
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server. An attacker could exploit this vulnerability by connecting to a wireless network that is configured for CWA and sending traffic through an affected device that should be denied by the configured ACL before user authentication. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device before the user authentication is completed, allowing the attacker to access trusted networks that the device might be protecting.
Published 2024-09-25 · Analyzed
9.3EPSS 0.003
CVE-2020-3229
Cisco IOS XE Software Web UI Privilege Escalation Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.053
CVE-2020-3218
Cisco IOS XE Software Web UI Remote Code Execution Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.049
CVE-2019-1753
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.038
CVE-2019-1756
Cisco IOS XE Software Command Injection Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.037
CVE-2019-1754
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.034
CVE-2019-1755
Cisco IOS XE Software Command Injection Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.034
CVE-2020-3219
Cisco IOS XE Software Web UI Command Injection Vulnerability
Published 2020-06-03 · Modified
9.0EPSS 0.033
CVE-2022-20719
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.027
CVE-2022-20718
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.024
CVE-2022-20723
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.021
CVE-2022-20720
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.015
CVE-2026-20267
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.0EPSS 0.003
CVE-2019-1743
Cisco IOS XE Software Arbitrary File Upload Vulnerability
Published 2019-03-27 · Modified
8.8EPSS 0.022
CVE-2020-3425
Cisco IOS XE Software Privilege Escalation Vulnerabilities
Published 2020-09-24 · Modified
8.8EPSS 0.018
CVE-2019-1745
Cisco IOS XE Software Command Injection Vulnerability
Published 2019-03-27 · Modified
8.8EPSS 0.004
CVE-2018-0472
Cisco IOS XE Software and Cisco ASA 5500-X Series Adaptive Security Appliance IPsec Denial of Service Vulnerability
Published 2018-10-05 · Modified
8.6EPSS 0.162
CVE-2019-1741
Cisco IOS XE Software Encrypted Traffic Analytics Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.028
CVE-2019-1752
Cisco IOS and IOS XE Software ISDN Interface Denial of Service Vulnerability
Published 2019-03-28 · Modified
8.6EPSS 0.025
CVE-2019-12658
Cisco IOS XE Software Filesystem Exhaustion Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12646
Cisco IOS XE Software NAT Session Initiation Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2020-3226
Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.016
CVE-2022-20683
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Application Visibility and Control Denial of Service Vulnerability
Published 2022-04-15 · Modified
8.6EPSS 0.015
CVE-2021-1446
Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2023-20027
Cisco IOS XE Software Virtual Fragmentation Reassembly Denial of Service Vulnerability
Published 2023-03-23 · Modified
8.6EPSS 0.010
CVE-2024-20436
A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulnerability by sending crafted HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, causing a DoS condition on the affected device.
Published 2024-09-25 · Analyzed
8.6EPSS 0.009
CVE-2020-3203
Cisco IOS XE Software Catalyst 9800 Series Wireless Controllers Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.008
CVE-2024-20314
A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain IPv4 packets. An attacker could exploit this vulnerability by sending certain IPv4 packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition.
Published 2024-03-27 · Analyzed
8.6EPSS 0.008
CVE-2023-20227
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2023-20033
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when processing traffic that is received on the management interface. An attacker could exploit this vulnerability by sending a high rate of traffic to the management interface. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2023-20187
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv6 multicast packets when they are fanned out more than seven times on an affected device. An attacker could exploit this vulnerability by sending a specific IPv6 multicast or IPv6 multicast VPN (MVPNv6) packet through the affected device. A successful exploit could allow the attacker to cause a reload of the affected device, resulting in a DoS condition.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2024-20480
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover. This vulnerability is due to improper handling of IPv4 DHCP packets. An attacker could exploit this vulnerability by sending certain IPv4 DHCP packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition that requires a manual reload to recover.
Published 2024-09-25 · Analyzed
8.6EPSS 0.006
CVE-2026-20301
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
Published 2026-08-05 · Analyzed
8.6EPSS 0.003
CVE-2026-20270
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20269
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20268
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
1 / 3Next →