VendorsCiscoios_xe17.2.1a
Vulnerabilities

Cisco IOS Xe 17.2.1a

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

84CVEs
CVE-2021-34770
Cisco IOS XE Software for Catalyst 9000 Family Wireless Controllers CAPWAP Remote Code Execution Vulnerability
Published 2021-09-23 · Analyzed
10.0EPSS 0.030
CVE-2021-1619
Cisco IOS XE Software NETCONF and RESTCONF Authentication Bypass Vulnerability
Published 2021-09-23 · Modified
9.8EPSS 0.018
CVE-2026-20272
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.8EPSS 0.004
CVE-2021-1433
Cisco IOS XE SD-WAN Software vDaemon Buffer Overflow Vulnerability
Published 2021-03-24 · Modified
9.3EPSS 0.023
CVE-2024-20510
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server. An attacker could exploit this vulnerability by connecting to a wireless network that is configured for CWA and sending traffic through an affected device that should be denied by the configured ACL before user authentication. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device before the user authentication is completed, allowing the attacker to access trusted networks that the device might be protecting.
Published 2024-09-25 · Analyzed
9.3EPSS 0.003
CVE-2025-20221
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the affected device. A successful exploit could allow the attacker to bypass the Layer 3 and Layer 4 traffic filters and inject a crafted packet into the network.
Published 2025-05-07 · Analyzed
9.1EPSS 0.005
CVE-2022-20719
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.027
CVE-2022-20718
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.024
CVE-2022-20723
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.021
CVE-2022-20693
Cisco IOS XE Software Web UI API Injection Vulnerability
Published 2022-04-15 · Modified
9.0EPSS 0.016
CVE-2022-20720
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
9.0EPSS 0.015
CVE-2026-20267
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
9.0EPSS 0.003
CVE-2020-3425
Cisco IOS XE Software Privilege Escalation Vulnerabilities
Published 2020-09-24 · Modified
8.8EPSS 0.018
CVE-2022-20683
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers Application Visibility and Control Denial of Service Vulnerability
Published 2022-04-15 · Modified
8.6EPSS 0.015
CVE-2021-1446
Cisco IOS XE Software DNS NAT Protocol Application Layer Gateway Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2021-1373
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
Published 2021-03-24 · Modified
8.6EPSS 0.015
CVE-2022-20682
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family CAPWAP Denial of Service Vulnerability
Published 2022-04-15 · Modified
8.6EPSS 0.013
CVE-2024-20259
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint analytics are enabled. An attacker could exploit this vulnerability by sending a crafted DHCP request through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Note: The attack vector is listed as network because a DHCP relay anywhere on the network could allow exploits from networks other than the adjacent one.
Published 2024-03-27 · Analyzed
8.6EPSS 0.008
CVE-2024-20314
A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain IPv4 packets. An attacker could exploit this vulnerability by sending certain IPv4 packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition.
Published 2024-03-27 · Analyzed
8.6EPSS 0.008
CVE-2024-20455
A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because UTD improperly handles certain packets as those packets egress an SD-WAN IPsec tunnel. An attacker could exploit this vulnerability by sending crafted traffic through an SD-WAN IPsec tunnel that is configured on an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Note: SD-WAN tunnels that are configured with Generic Routing Encapsulation (GRE) are not affected by this vulnerability.
Published 2024-09-25 · Analyzed
8.6EPSS 0.007
CVE-2023-20227
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2024-20480
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover. This vulnerability is due to improper handling of IPv4 DHCP packets. An attacker could exploit this vulnerability by sending certain IPv4 DHCP packets to an affected device. A successful exploit could allow the attacker to cause the device to exhaust CPU resources and stop processing traffic, resulting in a DoS condition that requires a manual reload to recover.
Published 2024-09-25 · Analyzed
8.6EPSS 0.006
CVE-2026-20301
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
Published 2026-08-05 · Analyzed
8.6EPSS 0.003
CVE-2026-20268
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20269
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20270
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2026-20273
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Analyzed
8.6EPSS 0.003
CVE-2026-20271
Cisco IOS XE Software Security Hardening Release
Published 2026-08-05 · Modified
8.6EPSS 0.003
CVE-2021-1443
Cisco IOS XE Software Web UI OS Command Injection Vulnerability
Published 2021-03-24 · Modified
8.5EPSS 0.023
CVE-2025-20200
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20197
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20198
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20199
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability by including crafted input in specific configuration commands. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system of an affected device. The security impact rating (SIR) of this advisory has been raised to High because an attacker could gain access to the underlying operating system of the affected device and perform potentially undetected actions. Note: The attacker must have privileges to enter configuration mode on the affected device. This is usually referred to as privilege level 15.
Published 2025-05-07 · Analyzed
8.2EPSS 0.002
CVE-2025-20160
A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine-in-the-middle attacker could exploit this vulnerability by intercepting and reading unencrypted TACACS+ messages or impersonating the TACACS+ server and falsely accepting arbitrary authentication requests. A successful exploit could allow the attacker to view sensitive information in a TACACS+ message or bypass authentication and gain access to the affected device.
Published 2025-09-24 · Analyzed
8.1EPSS 0.004
CVE-2021-1431
Cisco IOS XE SD-WAN Software vDaemon Denial of Service Vulnerability
Published 2021-03-24 · Modified
7.8EPSS 0.016
CVE-2021-1442
Cisco IOS XE Software Plug-and-Play Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.8EPSS 0.002
CVE-2022-20681
Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Catalyst 9000 Family Wireless Controllers Privilege Escalation Vulnerability
Published 2022-04-15 · Modified
7.8EPSS 0.002
CVE-2025-20352
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker with high privileges could execute code as the root user on an affected device that is running Cisco IOS XE Software. To execute code as the root user, the attacker must have the SNMPv1 or v2c read-only community string or valid SNMPv3 user credentials and administrative or privilege 15 credentials on the affected device. An attacker could exploit this vulnerability by sending a crafted SNMP packet to an affected device over IPv4 or IPv6 networks. This vulnerability is due to a stack overflow condition in the SNMP subsystem of the affected software. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Note: This vulnerability affects all versions of SNMP.
Published 2025-09-24 · Analyzed
7.7KEVEPSS 0.394
CVE-2022-20679
Cisco IOS XE Software IPSec Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.7EPSS 0.013
CVE-2022-20692
Cisco IOS XE Software NETCONF Over SSH Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.7EPSS 0.011
1 / 3Next →