VendorsCiscoios_xe3.2.0ja
Vulnerabilities

Cisco IOS Xe 3.2.0ja

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2017-12229
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software. The vulnerability is due to insufficient input validation for the REST API of the affected software. An attacker could exploit this vulnerability by sending a malicious API request to an affected device. A successful exploit could allow the attacker to bypass authentication and gain access to the web UI of the affected software. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuz46036.
Published 2017-09-28 · Modified
10.0EPSS 0.052
CVE-2017-12236
A vulnerability in the implementation of the Locator/ID Separation Protocol (LISP) in Cisco IOS XE 3.2 through 16.5 could allow an unauthenticated, remote attacker using an x tunnel router to bypass authentication checks performed when registering an Endpoint Identifier (EID) to a Routing Locator (RLOC) in the map server/map resolver (MS/MR). The vulnerability is due to a logic error introduced via a code regression for the affected software. An attacker could exploit this vulnerability by sending specific valid map-registration requests, which will be accepted by the MS/MR even if the authentication keys do not match, to the affected software. A successful exploit could allow the attacker to inject invalid mappings of EIDs to RLOCs in the MS/MR of the affected software. This vulnerability affects Cisco devices that are configured with LISP acting as an IPv4 or IPv6 map server. This vulnerability affects Cisco IOS XE Software release trains 3.9E and Everest 16.4. Cisco Bug IDs: CSCvc18008.
Published 2017-09-28 · Modified
9.8EPSS 0.031
CVE-2019-1753
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.038
CVE-2019-1756
Cisco IOS XE Software Command Injection Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.037
CVE-2019-1754
Cisco IOS XE Software Privilege Escalation Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.034
CVE-2019-1755
Cisco IOS XE Software Command Injection Vulnerability
Published 2019-03-28 · Modified
9.0EPSS 0.034
CVE-2019-1741
Cisco IOS XE Software Encrypted Traffic Analytics Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.028
CVE-2019-1738
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2019-1739
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2019-1740
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
Published 2019-03-27 · Modified
8.6EPSS 0.022
CVE-2016-6385
Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.
Published 2016-10-05 · Modified
7.8EPSS 0.033
CVE-2017-3856
A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a high number of requests to the web user interface of the affected software. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have access to the management interface of the affected software, which is typically connected to a restricted management network. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the web user interface of the software is enabled. By default, the web user interface is not enabled. Cisco Bug IDs: CSCup70353.
Published 2017-03-22 · Modified
7.8EPSS 0.025
CVE-2016-1384
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
Published 2016-04-20 · Modified
7.5EPSS 0.025
CVE-2019-1742
Cisco IOS XE Software Information Disclosure Vulnerability
Published 2019-03-27 · Modified
7.5EPSS 0.022
CVE-2019-1760
Cisco IOS XE Software Performance Routing Version 3 Denial of Service Vulnerability
Published 2019-03-28 · Modified
7.1EPSS 0.021
CVE-2019-1759
Cisco IOS XE Software Gigabit Ethernet Management Interface Access Control List Bypass Vulnerability
Published 2019-03-28 · Modified
5.3EPSS 0.044