VendorsCiscoios_xr6.5.3
Vulnerabilities

Cisco IOS Xr 6.5.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2025-20363
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device. For more information about this vulnerability, see the Details ["#details"] section of this advisory.
Published 2025-09-25 · Analyzed
9.0EPSS 0.069
CVE-2020-3118
Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
Published 2020-02-05 · Analyzed
8.8KEVEPSS 0.117
CVE-2024-20381
Cisco Network Services Orchestrator Configuration Update Authorization Bypass Vulnerability
Published 2024-09-11 · Analyzed
8.8EPSS 0.006
CVE-2024-20398
Cisco IOS XR Software Local Privilege Escalation Vulnerability
Published 2024-09-11 · Analyzed
8.8EPSS 0.002
CVE-2020-3569
Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerabilities
Published 2020-09-23 · Analyzed
8.6KEVEPSS 0.033
CVE-2025-20115
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
8.6EPSS 0.009
CVE-2025-20154
Cisco IOS, IOS XE and IOS XR Software TWAMP Denial of Service Vulnerability
Published 2025-05-07 · Analyzed
8.6EPSS 0.005
CVE-2019-16027
Cisco IOS XR Software Intermediate System–to–Intermediate System Denial of Service Vulnerability
Published 2020-01-26 · Modified
7.7EPSS 0.015
CVE-2025-20209
Cisco IOS XR Software Internet Key Exchange Version 2 Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
7.5EPSS 0.005
CVE-2020-3120
Cisco FXOS, IOS XR, and NX-OS Software Cisco Discovery Protocol Denial of Service Vulnerability
Published 2020-02-05 · Modified
7.4EPSS 0.016
CVE-2022-20849
Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.003
CVE-2025-20248
Cisco IOS XR Software Image Verification Bypass Vulnerability
Published 2025-09-10 · Analyzed
6.0EPSS 0.001
CVE-2025-20145
Cisco IOS XR Software Access Control List Bypass Vulnerability
Published 2025-03-12 · Analyzed
5.8EPSS 0.004
CVE-2025-20144
Cisco IOS XR Software Access Control List Bypass Vulnerability
Published 2025-03-12 · Analyzed
5.8EPSS 0.003
CVE-2024-20343
Cisco IOS XR Software CLI Arbitrary File Read Vulnerability
Published 2024-09-11 · Analyzed
5.5EPSS 0.001
CVE-2019-15998
Cisco IOS XR Software NETCONF Over Secure Shell ACL Bypass Vulnerability
Published 2019-11-26 · Modified
5.3EPSS 0.007
CVE-2022-20846
Cisco IOS XR Software Cisco Discovery Protocol Buffer Overflow Vulnerability
Published 2024-11-15 · Analyzed
4.3EPSS 0.010
CVE-2024-20319
A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of an affected device. This vulnerability is due to incorrect UDP forwarding programming when using SNMP with management plane protection. An attacker could exploit this vulnerability by attempting to perform an SNMP operation using broadcast as the destination address that could be processed by an affected device that is configured with an SNMP server. A successful exploit could allow the attacker to communicate to the device on the configured SNMP ports. Although an unauthenticated attacker could send UDP datagrams to the configured SNMP port, only an authenticated user can retrieve or modify data using SNMP requests.
Published 2024-03-13 · Analyzed
4.3EPSS 0.003