VendorsCiscoios_xrall versions
Vulnerabilities

Cisco IOS Xr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

198CVEs
CVE-2025-20209
Cisco IOS XR Software Internet Key Exchange Version 2 Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
7.5EPSS 0.005
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2019-16018
Cisco IOS XR Software EVPN Operational Routes Denial of Service Vulnerability
Published 2020-01-26 · Modified
7.4EPSS 0.011
CVE-2018-0241
A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadcast packets that are forwarded to an IPv4 helper address. An attacker could exploit this vulnerability by sending multiple UDP broadcast packets to the affected device. An exploit could allow the attacker to cause a buffer leak on the affected device, eventually resulting in a DoS condition requiring manual intervention to recover. This vulnerability affects all Cisco IOS XR platforms running 6.3.1, 6.2.3, or earlier releases of Cisco IOS XR Software when at least one IPv4 helper address is configured on an interface of the device. Cisco Bug IDs: CSCvi35625.
Published 2018-04-19 · Modified
7.4EPSS 0.008
CVE-2019-1849
Cisco IOS XR Software BGP MPLS-Based EVPN Denial of Service Vulnerability
Published 2019-05-16 · Modified
7.4EPSS 0.006
CVE-2019-1846
Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers MPLS OAM Denial of Service Vulnerability
Published 2019-05-16 · Modified
7.4EPSS 0.006
CVE-2019-1918
Cisco IOS XR Software Intermediate System–to–Intermediate System Denial of Service Vulnerability
Published 2019-08-07 · Modified
7.4EPSS 0.005
CVE-2021-1268
Cisco IOS XR Software IPv6 Flood Denial of Service Vulnerability
Published 2021-02-04 · Modified
7.4EPSS 0.005
CVE-2019-1910
Cisco IOS XR Software Intermediate System to Intermediate System Denial of Service Vulnerability
Published 2019-08-07 · Modified
7.4EPSS 0.004
CVE-2021-34714
Multiple Cisco Operating Systems Unidirectional Link Detection Denial of Service Vulnerability
Published 2021-09-23 · Modified
7.4EPSS 0.004
CVE-2021-34713
Cisco IOS XR Software for ASR 9000 Series Routers Denial of Service Vulnerability
Published 2021-09-09 · Modified
7.4EPSS 0.004
CVE-2024-20327
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of malformed PPPoE packets that are received on a router that is running Broadband Network Gateway (BNG) functionality with PPPoE termination on a Lightspeed-based or Lightspeed-Plus-based line card. An attacker could exploit this vulnerability by sending a crafted PPPoE packet to an affected line card interface that does not terminate PPPoE. A successful exploit could allow the attacker to crash the ppp_ma process, resulting in a DoS condition for PPPoE traffic across the router.
Published 2024-03-13 · Analyzed
7.4EPSS 0.003
CVE-2024-20406
Cisco IOS XR Software Intermediate System-to-Intermediate System Denial of Service Vulnerability
Published 2024-09-11 · Analyzed
7.4EPSS 0.002
CVE-2024-20317
Cisco IOS XR Software Layer 2 Services Denial of Service Vulnerability
Published 2024-09-11 · Analyzed
7.4EPSS 0.002
CVE-2025-20141
Cisco IOS XR Software Release 7.9.2 Denial of Service Vulnerabillity
Published 2025-03-12 · Analyzed
7.4EPSS 0.002
CVE-2026-20074
Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability
Published 2026-03-11 · Analyzed
7.4EPSS 0.002
CVE-2024-20483
Cisco IOS XR PON Controller Command Injection Vulnerabilities
Published 2024-09-11 · Analyzed
7.2EPSS 0.011
CVE-2017-6719
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3.10i.BASE.
Published 2017-07-04 · Modified
7.2EPSS 0.007
CVE-2019-1649
Cisco Secure Boot Hardware Tampering Vulnerability
Published 2019-05-13 · Modified
7.2EPSS 0.006
CVE-2019-12709
Cisco IOS XR Software for Cisco ASR 9000 VMAN CLI Privilege Escalation Vulnerability
Published 2019-09-25 · Modified
7.2EPSS 0.005
CVE-2017-6718
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2.1.26i.ROUT.
Published 2017-07-04 · Modified
7.2EPSS 0.004
CVE-2021-34722
Cisco IOS XR Software Command Injection Vulnerabilities
Published 2021-09-09 · Modified
7.2EPSS 0.003
CVE-2021-34708
Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-09-09 · Modified
7.2EPSS 0.002
CVE-2009-0637
The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command.
Published 2009-03-27 · Modified
7.1EPSS 0.033
CVE-2014-2176
Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928.
Published 2014-06-14 · Modified
7.1EPSS 0.028
CVE-2014-3353
Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a denial of service (CPU consumption and IPv6 packet drops) via a malformed IPv6 packet, aka Bug ID CSCuo95165.
Published 2014-09-04 · Modified
7.1EPSS 0.025
CVE-2008-1159
Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293.
Published 2008-05-22 · Modified
7.1EPSS 0.025
CVE-2015-0618
Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Carrier Routing System X (CRS-X) devices allows remote attackers to cause a denial of service (line-card reload) via malformed IPv6 packets with extension headers, aka Bug ID CSCuq95241.
Published 2015-02-21 · Modified
7.1EPSS 0.023
CVE-2012-4617
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
Published 2012-09-27 · Modified
7.1EPSS 0.023
CVE-2013-5549
Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.
Published 2013-10-25 · Modified
7.1EPSS 0.017
CVE-2022-20758
Cisco IOS XR Software Border Gateway Protocol Ethernet VPN Denial of Service Vulnerability
Published 2022-04-15 · Modified
7.1EPSS 0.012
CVE-2017-6728
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege level on an affected system, because of Incorrect Permissions. More Information: CSCvb99389. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.3.1.15i.BASE 6.2.3.1i.BASE 6.2.2.15i.BASE 6.1.4.10i.BASE.
Published 2017-07-10 · Modified
7.0EPSS 0.003
CVE-2023-20135
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses an ISO image. An attacker could exploit this vulnerability by modifying an ISO image and then carrying out install requests in parallel. A successful exploit could allow the attacker to execute arbitrary code on an affected device.
Published 2023-09-13 · Modified
7.0EPSS 0.001
CVE-2021-34721
Cisco IOS XR Software Command Injection Vulnerabilities
Published 2021-09-09 · Modified
6.9EPSS 0.003
CVE-2021-34709
Cisco IOS XR Software for Cisco 8000 and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-09-09 · Modified
6.9EPSS 0.002
CVE-2018-15428
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2018-10-05 · Modified
6.8EPSS 0.020
CVE-2019-1909
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2019-07-06 · Modified
6.8EPSS 0.015
CVE-2016-1366
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.
Published 2016-03-24 · Modified
6.8EPSS 0.014
CVE-2021-1440
Cisco IOS XR Software BGP Resource Public Key Infrastructure Denial of Service Vulnerability
Published 2024-11-18 · Analyzed
6.8EPSS 0.008
CVE-2021-1136
Cisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-02-04 · Modified
6.7EPSS 0.002
← Prev3 / 5Next →