VendorsCiscoios_xrany version
Vulnerabilities

Cisco IOS Xr any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

94CVEs
CVE-2013-1162
The traffic engineering (TE) processing subsystem in Cisco IOS XR allows remote attackers to cause a denial of service (process restart) via crafted TE packets, aka Bug ID CSCue04000.
Published 2013-03-26 · Modified
5.0EPSS 0.012
CVE-2013-1204
Memory leak in the SNMP process in Cisco IOS XR allows remote attackers to cause a denial of service (memory consumption or process reload) by sending many port-162 UDP packets, aka Bug ID CSCug80345.
Published 2013-05-23 · Modified
5.0EPSS 0.012
CVE-2015-0657
Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCur69192.
Published 2015-03-06 · Modified
5.0EPSS 0.012
CVE-2014-8014
Cisco IOS XR allows remote attackers to cause a denial of service (RSVP process reload) via a malformed RSVP packet, aka Bug ID CSCub63710.
Published 2014-12-18 · Modified
5.0EPSS 0.012
CVE-2014-8005
Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.
Published 2014-11-26 · Modified
5.0EPSS 0.012
CVE-2014-3335
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
Published 2014-08-26 · Modified
4.6EPSS 0.011
CVE-2023-20064
Cisco IOS XR Software Bootloader Unauthenticated Information Disclosure Vulnerability
Published 2023-03-09 · Modified
4.6EPSS 0.003
CVE-2020-3449
Cisco IOS XR Software Additional Paths Denial of Service Vulnerability
Published 2020-08-17 · Modified
4.3EPSS 0.011
CVE-2014-3342
The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka Bug IDs CSCuq42336, CSCuq76853, CSCuq76873, and CSCuq45383.
Published 2014-09-12 · Modified
4.0EPSS 0.011
CVE-2013-1216
Memory leak in the SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (memory consumption and process restart) via crafted SNMP packets, aka Bug ID CSCue31546.
Published 2013-04-29 · Modified
4.0EPSS 0.010
CVE-2013-1234
The SNMP module in Cisco IOS XR allows remote authenticated users to cause a denial of service (process restart) via crafted SNMP packets, aka Bug ID CSCue69472.
Published 2013-05-03 · Modified
4.0EPSS 0.010
CVE-2015-0661
The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858.
Published 2015-03-06 · Modified
4.0EPSS 0.010
CVE-2009-2056
Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
Published 2009-08-21 · Modified
3.3EPSS 0.013
CVE-2009-1154
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
Published 2009-08-21 · Modified
3.3EPSS 0.013
← Prev3 / 3