VendorsCiscoios_xrany version
Vulnerabilities

Cisco IOS Xr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

94CVEs
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2021-34713
Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
Published 2021-09-09 · Modified
7.4EPSS 0.004
CVE-2024-20327
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of malformed PPPoE packets that are received on a router that is running Broadband Network Gateway (BNG) functionality with PPPoE termination on a Lightspeed-based or Lightspeed-Plus-based line card. An attacker could exploit this vulnerability by sending a crafted PPPoE packet to an affected line card interface that does not terminate PPPoE. A successful exploit could allow the attacker to crash the ppp_ma process, resulting in a DoS condition for PPPoE traffic across the router.
Published 2024-03-13 · Analyzed
7.4EPSS 0.003
CVE-2024-20406
Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
Published 2024-09-11 · Analyzed
7.4EPSS 0.002
CVE-2026-20074
Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
Published 2026-03-11 · Analyzed
7.4EPSS 0.002
CVE-2019-12709
Cisco IOS XR Software for Cisco ASR 9000 VMAN CLI Privilege Escalation Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.005
CVE-2021-34722
Cisco IOS XR Software Command Injection Vulnerabilities
Published 2021-09-09 · Modified
7.2EPSS 0.003
CVE-2021-34708
Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-09-09 · Modified
7.2EPSS 0.002
CVE-2014-3353
Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a denial of service (CPU consumption and IPv6 packet drops) via a malformed IPv6 packet, aka Bug ID CSCuo95165.
Published 2014-09-04 · Modified
7.1EPSS 0.025
CVE-2008-1159
Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293.
Published 2008-05-22 · Modified
7.1EPSS 0.025
CVE-2022-20758
Cisco IOS XR Software Border Gateway Protocol Ethernet VPN Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.1EPSS 0.012
CVE-2017-6728
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege level on an affected system, because of Incorrect Permissions. More Information: CSCvb99389. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.3.1.15i.BASE 6.2.3.1i.BASE 6.2.2.15i.BASE 6.1.4.10i.BASE.
Published 2017-07-10 · Modified
7.0EPSS 0.003
CVE-2023-20135
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses an ISO image. An attacker could exploit this vulnerability by modifying an ISO image and then carrying out install requests in parallel. A successful exploit could allow the attacker to execute arbitrary code on an affected device.
Published 2023-09-13 · Modified
7.0EPSS 0.001
CVE-2021-34721
Cisco IOS XR Software Command Injection Vulnerabilities
Published 2021-09-09 · Modified
6.9EPSS 0.003
CVE-2021-34709
Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-09-09 · Modified
6.9EPSS 0.002
CVE-2019-1909
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2019-07-06 · Modified
6.8EPSS 0.015
CVE-2021-1440
Cisco IOS XR Software BGP Resource Public Key Infrastructure Denial of Service Vulnerability
Published 2024-11-18 · Analyzed
6.8EPSS 0.008
CVE-2021-1136
Cisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-02-04 · Modified
6.7EPSS 0.002
CVE-2021-1244
Cisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-02-04 · Modified
6.7EPSS 0.002
CVE-2025-20177
Cisco IOS XR Software Image Verification Bypass Vulnerability
Published 2025-03-12 · Analyzed
6.7EPSS 0.002
CVE-2025-20143
Cisco IOS XR Software Secure Boot Bypass Vulnerability
Published 2025-03-12 · Analyzed
6.7EPSS 0.001
CVE-2022-20821
Cisco IOS XR Software Health Check Open Port Vulnerability
Published 2022-05-26 · Analyzed
6.5KEVEPSS 0.115
CVE-2021-1389
Cisco IOS XR and Cisco NX-OS Software IPv6 Access Control List Bypass Vulnerability
Published 2021-02-04 · Modified
6.5EPSS 0.012
CVE-2023-20233
A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs). An attacker could exploit this vulnerability by sending crafted CCMs to an affected device. A successful exploit could allow the attacker to cause the CFM service to crash when a user displays information about maintenance end points (MEPs) for peer MEPs on an affected device.
Published 2023-09-13 · Modified
6.5EPSS 0.003
CVE-2014-3308
Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.
Published 2014-07-07 · Modified
6.4EPSS 0.028
CVE-2014-3322
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.
Published 2014-07-24 · Modified
6.1EPSS 0.012
CVE-2014-2144
Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266.
Published 2014-04-05 · Modified
6.1EPSS 0.007
CVE-2020-3190
Cisco IOS XR Software IPsec Packet Processor Denial of Service Vulnerability
Published 2020-03-04 · Modified
5.8EPSS 0.013
CVE-2023-20190
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to incorrect destination address range encoding in the compression module of an ACL that is applied to an interface of an affected device. An attacker could exploit this vulnerability by sending traffic through the affected device that should be denied by the configured ACL. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device, allowing the attacker to access trusted networks that the device might be protecting. There are workarounds that address this vulnerability. This advisory is part of the September 2023 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2023 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication .
Published 2023-09-13 · Modified
5.8EPSS 0.007
CVE-2014-3321
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
Published 2014-07-18 · Modified
5.7EPSS 0.006
CVE-2021-1128
Cisco IOS XR Software Unauthorized Information Disclosure Vulnerability
Published 2021-02-04 · Modified
5.5EPSS 0.003
CVE-2021-34771
Cisco IOS XR Software Unauthorized Information Disclosure Vulnerability
Published 2021-09-09 · Modified
5.5EPSS 0.003
CVE-2024-20390
Cisco IOS XR Software Dedicated XML Agent TCP Denial of Service Vulnerability
Published 2024-09-11 · Analyzed
5.3EPSS 0.004
CVE-2007-4430
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Published 2007-08-20 · Modified
5.01 PoCEPSS 0.133
CVE-2013-3470
The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731.
Published 2013-08-30 · Modified
5.0EPSS 0.030
CVE-2013-5498
The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attackers to cause a denial of service (module reset) via crafted packet streams, aka Bug ID CSCue91963.
Published 2013-09-27 · Modified
5.0EPSS 0.023
CVE-2014-3270
The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924.
Published 2014-05-20 · Modified
5.0EPSS 0.020
CVE-2014-3271
The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug IDs CSCum85558, CSCum20949, CSCul61849, and CSCul71149.
Published 2014-05-20 · Modified
5.0EPSS 0.020
CVE-2014-8004
Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.
Published 2014-11-25 · Modified
5.0EPSS 0.016
CVE-2013-1204
Memory leak in the SNMP process in Cisco IOS XR allows remote attackers to cause a denial of service (memory consumption or process reload) by sending many port-162 UDP packets, aka Bug ID CSCug80345.
Published 2013-05-23 · Modified
5.0EPSS 0.012
← Prev2 / 3Next →