VendorsCiscoios_xr7.4.1
Vulnerabilities

Cisco IOS Xr 7.4.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2026-20274
Cisco IOS XR Software Security Hardening Release: September 2026
Published 2026-09-02 · Analyzed
9.8EPSS 0.007
CVE-2024-20381
Cisco Network Services Orchestrator Configuration Update Authorization Bypass Vulnerability
Published 2024-09-11 · Analyzed
8.8EPSS 0.006
CVE-2026-20280
Cisco IOS XR Software Security Hardening Release: September 2026
Published 2026-09-02 · Analyzed
8.8EPSS 0.003
CVE-2024-20398
Cisco IOS XR Software Local Privilege Escalation Vulnerability
Published 2024-09-11 · Analyzed
8.8EPSS 0.002
CVE-2025-20115
Cisco IOS XR Software Border Gateway Protocol Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
8.6EPSS 0.009
CVE-2025-20142
Cisco IOS XR Software for ASR 9000 Series Routers L2VPN Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
8.6EPSS 0.005
CVE-2025-20154
Cisco IOS, IOS XE and IOS XR Software TWAMP Denial of Service Vulnerability
Published 2025-05-07 · Analyzed
8.6EPSS 0.005
CVE-2026-20276
Cisco IOS XR Software Security Hardening Release: September 2026
Published 2026-09-02 · Analyzed
8.6EPSS 0.003
CVE-2024-20320
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of arguments that are included with the SSH client CLI command. An attacker with low-privileged access to an affected device could exploit this vulnerability by issuing a crafted SSH client command to the CLI. A successful exploit could allow the attacker to elevate privileges to root on the affected device.
Published 2024-03-13 · Analyzed
7.8EPSS 0.002
CVE-2025-20209
Cisco IOS XR Software Internet Key Exchange Version 2 Denial of Service Vulnerability
Published 2025-03-12 · Analyzed
7.5EPSS 0.005
CVE-2022-20849
Cisco IOS XR Software Broadband Network Gateway PPPoE Denial of Service Vulnerability
Published 2024-11-15 · Analyzed
6.1EPSS 0.003
CVE-2025-20248
Cisco IOS XR Software Image Verification Bypass Vulnerability
Published 2025-09-10 · Analyzed
6.0EPSS 0.001
CVE-2025-20145
Cisco IOS XR Software Access Control List Bypass Vulnerability
Published 2025-03-12 · Analyzed
5.8EPSS 0.004
CVE-2025-20144
Cisco IOS XR Software Access Control List Bypass Vulnerability
Published 2025-03-12 · Analyzed
5.8EPSS 0.003
CVE-2024-20343
Cisco IOS XR Software CLI Arbitrary File Read Vulnerability
Published 2024-09-11 · Analyzed
5.5EPSS 0.001
CVE-2022-20846
Cisco IOS XR Software Cisco Discovery Protocol Buffer Overflow Vulnerability
Published 2024-11-15 · Analyzed
4.3EPSS 0.010
CVE-2024-20319
A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of an affected device. This vulnerability is due to incorrect UDP forwarding programming when using SNMP with management plane protection. An attacker could exploit this vulnerability by attempting to perform an SNMP operation using broadcast as the destination address that could be processed by an affected device that is configured with an SNMP server. A successful exploit could allow the attacker to communicate to the device on the configured SNMP ports. Although an unauthenticated attacker could send UDP datagrams to the configured SNMP port, only an authenticated user can retrieve or modify data using SNMP requests.
Published 2024-03-13 · Analyzed
4.3EPSS 0.003