cbcvebase.

Cisco Ios Xe Software vulnerabilities

236 known vulnerabilities affecting cisco/cisco_ios_xe_software.

Total CVEs
236
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
9
Severity breakdown
CRITICAL10HIGH135MEDIUM91

Vulnerabilities

Page 1 of 12
CVE-2023-20198P1CRITICALCVSS 10.0KEVPoCRansomwarev16.1.1v16.1.2+184 more2023-10-16
CVE-2023-20198 [CRITICAL] CWE-420 CVE-2023-20198: Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gai
nvd
CVE-2023-20273P1HIGHCVSS 7.2KEVPoCv16.1.1v16.1.2+184 more2023-10-25
CVE-2023-20273 [HIGH] CWE-78 CVE-2023-20273: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to inje
nvd
CVE-2025-20352P1HIGHCVSS 7.7KEVv3.5.0Ev3.5.1E+347 more2025-09-24
CVE-2025-20352 [HIGH] CWE-121 CVE-2025-20352: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS,
nvd
CVE-2017-6742P1HIGHCVSS 8.8KEVv3.7.0Sv3.7.1S+90 more2017-07-17
CVE-2017-6742 [HIGH] CWE-119 CVE-2017-6742: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerabili
nvd
CVE-2017-6738P1HIGHCVSS 8.8KEVv3.2.0SGv3.2.1SG+89 more2017-07-17
CVE-2017-6738 [HIGH] CWE-119 CVE-2017-6738: The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains mu The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected
nvd
CVE-2023-20109P2MEDIUMCVSS 6.6KEVv3.7.0Sv3.7.1S+362 more2023-09-27
CVE-2023-20109 [MEDIUM] CWE-787 CVE-2023-20109: A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software a A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to i
nvd
CVE-2025-20188P1CRITICALCVSS 10.0ExploitedPoCv17.11.1v17.12.1+5 more2025-05-07
CVE-2025-20188 [CRITICAL] CWE-798 CVE-2025-20188: A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recordin A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a har
nvd
CVE-2025-20363P1CRITICALCVSS 9.0Exploitedv3.2.0SGv3.2.1SG+454 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
nvd
CVE-2021-1435P3HIGHCVSS 7.2Exploitedvn/a2021-03-24
CVE-2021-1435 [HIGH] CWE-22 CVE-2021-1435: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted request to the web UI of an affected device with arbitrary co
nvd
CVE-2019-12624P2HIGHCVSS 8.8PoCv3.xE2019-08-21
CVE-2019-12624 [HIGH] CWE-352 CVE-2019-12624: A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Contro A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management
nvd
CVE-2019-12643P2CRITICALCVSS 10.0≥ unspecified, < 16.09.032019-08-28
CVE-2019-12643 [CRITICAL] CWE-287 CVE-2019-12643: A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allo A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploi
nvd
CVE-2021-1451P2CRITICALCVSS 9.8vn/a2021-03-24
CVE-2021-1451 [CRITICAL] CWE-119 CVE-2021-1451: A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisc A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying Linux operating system of an affected device. The vulnerability is due to incorrect b
nvd
CVE-2021-1384P2HIGHCVSS 7.2vn/a2021-03-24
CVE-2021-1384 [HIGH] CWE-77 CVE-2021-1384: A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user. This vulnerability is due to incomplete validation of fields in the application packages loaded onto IOx. An attacker could exploit this vulnerability
nvd
CVE-2021-34770P2CRITICALCVSS 9.8vn/a2021-09-23
CVE-2021-34770 [CRITICAL] CWE-122 CVE-2021-34770: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processi A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected devi
nvd
CVE-2025-20221P2CRITICALCVSS 9.1v16.12.13v17.1.1+87 more2025-05-07
CVE-2025-20221 [CRITICAL] CWE-200 CVE-2025-20221: A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unau A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by sending a crafted packet to the aff
nvd
CVE-2025-20186P2HIGHCVSS 8.8v16.12.8v16.12.4+74 more2025-05-07
CVE-2025-20186 [HIGH] CWE-78 CVE-2025-20186: A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisc A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, remote attacker with a lobby ambassador user account to perform a command injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit t
nvd
CVE-2025-20334P2HIGHCVSS 8.8v17.9.5v17.9.5a+36 more2025-09-24
CVE-2025-20334 [HIGH] CWE-77 CVE-2025-20334: A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with root privileges into the underlying operating system. This vulnerability is due to insufficient input validation. An attacker with administrative privileges could exploit this vulnerability by authenticating to an af
nvd
CVE-2017-6741P2HIGHCVSS 8.8v3.7.0Sv3.7.1S+86 more2017-07-17
CVE-2017-6741 [HIGH] CWE-119 CVE-2017-6741: A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. The vulnerability is due to a buffer overflow in the affected code area. The vulnerabili
nvd
CVE-2019-1753P2HIGHCVSS 8.8v3.6.10Ev16.1.1+36 more2019-03-28
CVE-2019-1753 [HIGH] CWE-20 CVE-2019-1753: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by su
nvd
CVE-2021-1619P2CRITICALCVSS 9.1vn/a2021-09-23
CVE-2021-1619 [CRITICAL] CWE-824 CVE-2021-1619: A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory corruption that results in a denia
nvd
1 / 12Next →