Cisco Asr 5000 Series Software vulnerabilities
15 known vulnerabilities affecting cisco/cisco_asr_5000_series_software.
Total CVEs
15
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2021-1424MEDIUMCVSS 5.3v21.15.7v21.13.10+220 more2024-11-18
CVE-2021-1424 [MEDIUM] CWE-119 CVE-2021-1424: A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow
A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could exploit this vulnerability by sending specifi
cvelistv5nvd
CVE-2023-20046HIGHCVSS 8.8v21.11.0v21.11.1+402 more2023-05-09
CVE-2023-20046 [HIGH] CWE-289 CVE-2023-20046: A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device.
This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an af
cvelistv5nvd
CVE-2023-20051HIGHCVSS 7.5vn/a2023-04-05
CVE-2023-20051 [MEDIUM] CWE-400 CVE-2023-20051: A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) coul
A vulnerability in the Vector Packet Processor (VPP) of Cisco Packet Data Network Gateway (PGW) could allow an unauthenticated, remote attacker to stop ICMP traffic from being processed over an IPsec connection. This vulnerability is due to the VPP improperly handling a malformed packet. An attacker could exploit this vulnerability by sending a malf
cvelistv5nvd
CVE-2022-20665MEDIUMCVSS 6.7vn/a2022-04-06
CVE-2022-20665 [MEDIUM] CWE-77 CVE-2022-20665: A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate p
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute a
cvelistv5nvd
CVE-2021-1539HIGHCVSS 8.8vn/a2021-06-04
CVE-2021-1539 [HIGH] CWE-863 CVE-2021-1539: Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) cou
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2021-1540HIGHCVSS 7.2vn/a2021-06-04
CVE-2021-1540 [HIGH] CWE-863 CVE-2021-1540: Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) cou
Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
cvelistv5nvd
CVE-2021-1378HIGHCVSS 7.5vn/a2021-02-17
CVE-2021-1378 [MEDIUM] CWE-400 CVE-2021-1378: A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticat
A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vuln
cvelistv5nvd
CVE-2021-1353HIGHCVSS 8.6vn/a2021-01-20
CVE-2021-1353 [MEDIUM] CWE-401 CVE-2021-1353: A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote
A vulnerability in the IPv4 protocol handling of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to a memory leak that occurs during packet processing. An attacker could exploit this vulnerability by sending a series of crafted IPv4 packets throug
cvelistv5nvd
CVE-2021-1145MEDIUMCVSS 6.5vn/a2021-01-13
CVE-2021-1145 [MEDIUM] CWE-61 CVE-2021-1145: A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could all
A vulnerability in the Secure FTP (SFTP) of Cisco StarOS for Cisco ASR 5000 Series Routers could allow an authenticated, remote attacker to read arbitrary files on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the affected device. The vulnerability is due to insecure handling of symbolic links.
cvelistv5nvd
CVE-2020-3602MEDIUMCVSS 6.7vn/a2020-10-08
CVE-2020-3602 [MEDIUM] CWE-20 CVE-2020-3602: A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. The vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successfu
cvelistv5nvd
CVE-2020-3601MEDIUMCVSS 6.7vn/a2020-10-08
CVE-2020-3601 [MEDIUM] CWE-20 CVE-2020-3601: A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could
A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. The vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successfu
cvelistv5nvd
CVE-2020-3500HIGHCVSS 8.6vn/a2020-08-17
CVE-2020-3500 [MEDIUM] CWE-119 CVE-2020-3500: A vulnerability in the IPv6 implementation of Cisco StarOS could allow an unauthenticated, remote at
A vulnerability in the IPv6 implementation of Cisco StarOS could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient validation of incoming IPv6 traffic. An attacker could exploit this vulnerability by sending a crafted IPv6 packet to an affected device
cvelistv5nvd
CVE-2020-3244MEDIUMCVSS 5.3vn/a2020-06-18
CVE-2020-3244 [MEDIUM] CWE-20 CVE-2020-3244: A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggreg
A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is due to insufficient input validation of user traffic going through an affected device. An attack
cvelistv5nvd
CVE-2019-16026MEDIUMCVSS 5.9≥ unspecified, < n/a2020-01-26
CVE-2019-16026 [MEDIUM] CWE-20 CVE-2019-16026: A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mo
A vulnerability in the implementation of the Stream Control Transmission Protocol (SCTP) on Cisco Mobility Management Entity (MME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an eNodeB that is connected to an affected device. The vulnerability is due to insufficient input validation of SCTP traffic.
cvelistv5nvd
CVE-2019-1869HIGHCVSS 7.5≥ unspecified, < 21.11.12019-06-20
CVE-2019-1869 [HIGH] CWE-824 CVE-2019-1869: A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system
A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific
cvelistv5nvd