VendorsCiscoios_xrall versions
Vulnerabilities

Cisco IOS Xr

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

198CVEs
CVE-2021-1244
Cisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Image Verification Vulnerabilities
Published 2021-02-04 · Modified
6.7EPSS 0.002
CVE-2024-20456
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected device. This vulnerability is due to an error in the software build process. An attacker could exploit this vulnerability by manipulating the system’s configuration options to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass of the requirement to run Cisco signed images or alter the security properties of the running system.
Published 2024-07-10 · Analyzed
6.7EPSS 0.002
CVE-2025-20177
Cisco IOS XR Software Image Verification Bypass Vulnerability
Published 2025-03-12 · Analyzed
6.7EPSS 0.002
CVE-2025-20143
Cisco IOS XR Software Secure Boot Bypass Vulnerability
Published 2025-03-12 · Analyzed
6.7EPSS 0.001
CVE-2022-20821
Cisco IOS XR Software Health Check Open Port Vulnerability
Published 2022-05-26 · Analyzed
6.5KEVEPSS 0.115
CVE-2021-1389
Cisco IOS XR and Cisco NX-OS Software IPv6 Access Control List Bypass Vulnerability
Published 2021-02-04 · Modified
6.5EPSS 0.012
CVE-2023-20233
A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs). An attacker could exploit this vulnerability by sending crafted CCMs to an affected device. A successful exploit could allow the attacker to cause the CFM service to crash when a user displays information about maintenance end points (MEPs) for peer MEPs on an affected device.
Published 2023-09-13 · Modified
6.5EPSS 0.003
CVE-2014-3308
Cisco IOS XR on Trident line cards in ASR 9000 devices lacks a static punt policer, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted packets, aka Bug ID CSCun83985.
Published 2014-07-07 · Modified
6.4EPSS 0.028
CVE-2014-3322
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.
Published 2014-07-24 · Modified
6.1EPSS 0.012
CVE-2014-3379
Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (NPU and card hang or reload) via a malformed MPLS packet, aka Bug ID CSCuq10466.
Published 2014-09-20 · Modified
6.1EPSS 0.009
CVE-2014-2144
Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266.
Published 2014-04-05 · Modified
6.1EPSS 0.007
CVE-2022-20849
Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.003
CVE-2017-6666
A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) tunnels, resulting in a denial of service (DoS) condition. More Information: CSCvd16665. Known Affected Releases: 6.2.11.BASE. Known Fixed Releases: 6.1.3 6.1.2 6.3.1.8i.BASE 6.2.11.8i.BASE 6.2.2.9i.BASE 6.1.32.11i.BASE 6.1.31.10i.BASE 6.1.4.3i.BASE.
Published 2017-06-13 · Modified
6.0EPSS 0.003
CVE-2025-20248
Cisco IOS XR Software Image Verification Bypass Vulnerability
Published 2025-09-10 · Analyzed
6.0EPSS 0.001
CVE-2009-2055
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
Published 2009-08-19 · Analyzed
5.9KEVEPSS 0.033
CVE-2020-3190
Cisco IOS XR Software IPsec Packet Processor Denial of Service Vulnerability
Published 2020-03-04 · Modified
5.8EPSS 0.013
CVE-2023-20190
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to incorrect destination address range encoding in the compression module of an ACL that is applied to an interface of an affected device. An attacker could exploit this vulnerability by sending traffic through the affected device that should be denied by the configured ACL. A successful exploit could allow the attacker to bypass configured ACL protections on the affected device, allowing the attacker to access trusted networks that the device might be protecting. There are workarounds that address this vulnerability. This advisory is part of the September 2023 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: September 2023 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication .
Published 2023-09-13 · Modified
5.8EPSS 0.007
CVE-2024-20322
A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to improper assignment of lookup keys to internal interface contexts. An attacker could exploit this vulnerability by attempting to send traffic through an affected device. A successful exploit could allow the attacker to access resources behind the affected device that were supposed to be protected by a configured ACL.
Published 2024-03-13 · Analyzed
5.8EPSS 0.005
CVE-2025-20145
Cisco IOS XR Software Access Control List Bypass Vulnerability
Published 2025-03-12 · Analyzed
5.8EPSS 0.004
CVE-2025-20144
Cisco IOS XR Software Access Control List Bypass Vulnerability
Published 2025-03-12 · Analyzed
5.8EPSS 0.003
CVE-2015-4205
Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.
Published 2015-06-23 · Modified
5.7EPSS 0.009
CVE-2014-3321
Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149.
Published 2014-07-18 · Modified
5.7EPSS 0.006
CVE-2021-1128
Cisco IOS XR Software Unauthorized Information Disclosure Vulnerability
Published 2021-02-04 · Modified
5.5EPSS 0.003
CVE-2021-34771
Cisco IOS XR Software Unauthorized Information Disclosure Vulnerability
Published 2021-09-09 · Modified
5.5EPSS 0.003
CVE-2024-20343
Cisco IOS XR Software CLI Arbitrary File Read Vulnerability
Published 2024-09-11 · Analyzed
5.5EPSS 0.001
CVE-2009-0629
The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over TCP (XOT), and (10) X.25 Routing features in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (device reload) via a series of crafted TCP packets.
Published 2009-03-27 · Modified
5.4EPSS 0.040
CVE-2018-0286
A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on affected system. The vulnerability is due to improper handling of malformed requests processed by the netconf process. An attacker could exploit this vulnerability by sending malicious requests to the affected software. An exploit could allow the attacker to cause the targeted process to restart, resulting in a DoS condition on the affected system. Cisco Bug IDs: CSCvg95792.
Published 2018-05-02 · Modified
5.3EPSS 0.032
CVE-2017-12355
A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause one of the LPTS processes on an affected system to restart unexpectedly, resulting in a brief denial of service (DoS) condition. The vulnerability is due to incomplete LPTS frame validation by the affected software. An attacker could exploit this vulnerability by sending crafted XML requests to the management interface of an affected system. A successful exploit could allow the attacker to cause one of the LPTS processes on the affected system to restart unexpectedly, which would impact LPTS traffic and cause a brief DoS condition while the process restarts. Cisco Bug IDs: CSCvf76332.
Published 2017-11-30 · Modified
5.3EPSS 0.031
CVE-2017-6599
A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash due to a system memory leak, resulting in a denial of service (DoS) condition. This vulnerability affects Cisco IOS XR Software with gRPC enabled. More Information: CSCvb14433. Known Affected Releases: 6.1.1.BASE 6.2.1.BASE. Known Fixed Releases: 6.2.1.22i.MGBL 6.1.22.9i.MGBL 6.1.21.12i.MGBL 6.1.2.13i.MGBL.
Published 2017-04-07 · Modified
5.3EPSS 0.020
CVE-2016-1376
Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548.
Published 2016-04-12 · Modified
5.3EPSS 0.017
CVE-2016-6421
Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID CSCvb05643.
Published 2016-10-05 · Modified
5.3EPSS 0.016
CVE-2016-1433
Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packets, aka Bug ID CSCuz66289.
Published 2016-09-18 · Modified
5.3EPSS 0.016
CVE-2020-3364
Cisco IOS XR Software Standby Route Processor Gigabit Ethernet Management Interface Access Control List Bypass Vulnerability
Published 2020-06-18 · Modified
5.3EPSS 0.009
CVE-2016-1361
Cisco IOS XR through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices does not properly check for a Bidirectional Forwarding Detection (BFD) header in a UDP packet, which allows remote attackers to cause a denial of service (line-card restart) via a crafted packet, aka Bug ID CSCuw56900.
Published 2016-03-12 · Modified
5.3EPSS 0.007
CVE-2019-15998
Cisco IOS XR Software NETCONF Over Secure Shell ACL Bypass Vulnerability
Published 2019-11-26 · Modified
5.3EPSS 0.007
CVE-2024-20390
Cisco IOS XR Software Dedicated XML Agent TCP Denial of Service Vulnerability
Published 2024-09-11 · Analyzed
5.3EPSS 0.004
CVE-2007-4430
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
Published 2007-08-20 · Modified
5.01 PoCEPSS 0.133
CVE-2013-3470
The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731.
Published 2013-08-30 · Modified
5.0EPSS 0.030
CVE-2015-4191
Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 packet, aka Bug ID CSCuq95565.
Published 2015-06-19 · Modified
5.0EPSS 0.030
CVE-2015-4223
Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478.
Published 2015-06-25 · Modified
5.0EPSS 0.025
← Prev4 / 5Next →