VendorsCiscoios_xr24.2.1
Vulnerabilities

Cisco IOS Xr 24.2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-20274
Cisco IOS XR Software Security Hardening Release: September 2026
Published 2026-09-02 · Analyzed
9.8EPSS 0.007
CVE-2024-20381
Cisco Network Services Orchestrator Configuration Update Authorization Bypass Vulnerability
Published 2024-09-11 · Analyzed
8.8EPSS 0.006
CVE-2026-20280
Cisco IOS XR Software Security Hardening Release: September 2026
Published 2026-09-02 · Analyzed
8.8EPSS 0.003
CVE-2025-20115
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
8.6EPSS 0.009
CVE-2024-20304
Cisco IOS XR Software Packet Memory Exhaustion Vulnerability
Published 2024-09-11 · Analyzed
8.6EPSS 0.006
CVE-2025-20146
Cisco IOS XR Software for ASR 9000 Series Routers Layer 3 Multicast Routing Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
8.6EPSS 0.005
CVE-2025-20154
Cisco IOS, IOS XE and IOS XR Software TWAMP Denial of Service Vulnerability
Published 2025-05-07 · Analyzed
8.6EPSS 0.005
CVE-2026-20276
Cisco IOS XR Software Security Hardening Release: September 2026
Published 2026-09-02 · Analyzed
8.6EPSS 0.003
CVE-2024-20489
Cisco Routed Passive Optical Network Cleartext Password Vulnerability
Published 2024-09-11 · Analyzed
8.4EPSS 0.001
CVE-2025-20209
Cisco IOS XR Software Internet Key Exchange Version 2 Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
7.5EPSS 0.005
CVE-2024-20483
Cisco IOS XR PON Controller Command Injection Vulnerabilities
Published 2024-09-11 · Analyzed
7.2EPSS 0.011
CVE-2024-20456
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected device. This vulnerability is due to an error in the software build process. An attacker could exploit this vulnerability by manipulating the system’s configuration options to bypass some of the integrity checks that are performed during the booting process. A successful exploit could allow the attacker to control the boot configuration, which could enable them to bypass of the requirement to run Cisco signed images or alter the security properties of the running system.
Published 2024-07-10 · Analyzed
6.7EPSS 0.002
CVE-2025-20248
Cisco IOS XR Software Image Verification Bypass Vulnerability
Published 2025-09-10 · Analyzed
6.0EPSS 0.001
CVE-2025-20145
Cisco IOS XR Software Access Control List Bypass Vulnerability
Published 2025-03-12 · Analyzed
5.8EPSS 0.004