VendorsCiscoios_xe17.17.1
Vulnerabilities

Cisco IOS Xe 17.17.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-20272
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.8EPSS 0.006
CVE-2026-20267
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.0EPSS 0.004
CVE-2026-20268
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.005
CVE-2026-20269
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.005
CVE-2026-20270
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.005
CVE-2026-20271
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.005
CVE-2026-20273
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Analyzed
8.6EPSS 0.005
CVE-2025-20352
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP.
Published 2025-09-24 · Analyzed
7.7KEVEPSS 0.394
CVE-2026-20124
Cisco IOS XE Software SNMP Denial of Service Vulnerability
Published 2026-08-05 · Analyzed
7.7EPSS 0.005
CVE-2025-20312
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.
Published 2025-09-24 · Undergoing Analysis
7.7EPSS 0.004
CVE-2025-20313
Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. These vulnerabilities are due path traversal and improper image integrity validation. A successful exploit could allow the attacker to execute persistent code on the underlying operating system. Because this allows the attacker to bypass a major security feature of the device, Cisco has raised the Security Impact Rating (SIR) of this advisory from Medium to High. For more information about these vulnerabilities, see the Details ["#details"] section of this advisory. ERP
Published 2025-09-24 · Analyzed
6.7EPSS 0.002