Cisco Ios Xe Software vulnerabilities

238 known vulnerabilities affecting cisco/cisco_ios_xe_software.

Total CVEs
238
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH136MEDIUM92

Vulnerabilities

Page 11 of 12
CVE-2020-3476MEDIUMCVSS 6.0vn/a2020-09-24
CVE-2020-3476 [MEDIUM] CWE-552 CVE-2020-3476: A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing t
cvelistv5nvd
CVE-2019-12664HIGHCVSS 7.5≥ unspecified, < n/a2019-09-25
CVE-2019-12664 [HIGH] CWE-200 CVE-2019-12664: A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Ci A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to successful PPP authentication. The vulnerability is due to insufficient validation of the state of
cvelistv5nvd
CVE-2019-12663HIGHCVSS 8.6≥ unspecified, < n/a2019-09-25
CVE-2019-12663 [HIGH] CWE-20 CVE-2019-12663: A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of attributes in RADIUS messages. An attacke
cvelistv5nvd
CVE-2019-12646HIGHCVSS 7.5≥ unspecified, < 3.2.11aSG2019-09-25
CVE-2019-12646 [HIGH] CWE-399 CVE-2019-12646: A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Applicati A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected devi
cvelistv5nvd
CVE-2019-12653HIGHCVSS 7.5≥ unspecified, < n/a2019-09-25
CVE-2019-12653 [HIGH] CWE-20 CVE-2019-12653: A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthen A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsing of Raw Socket Transport payloads. An attacker could exploit this vulnerability by establish
cvelistv5nvd
CVE-2019-12661MEDIUMCVSS 6.7≥ unspecified, < n/a2019-09-25
CVE-2019-12661 [MEDIUM] CWE-77 CVE-2019-12661: A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software coul A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific VMAN CLI command on th
cvelistv5nvd
CVE-2019-12643CRITICALCVSS 10.0≥ unspecified, < 16.09.032019-08-28
CVE-2019-12643 [CRITICAL] CWE-287 CVE-2019-12643: A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allo A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploi
cvelistv5nvd
CVE-2019-12624HIGHCVSS 8.8PoCv3.xE2019-08-21
CVE-2019-12624 [HIGH] CWE-352 CVE-2019-12624: A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Contro A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management
cvelistv5nvd
CVE-2019-1904HIGHCVSS 8.8≥ unspecified, < 16.4.12019-06-21
CVE-2019-1904 [HIGH] CWE-352 CVE-2019-1904: A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a use
cvelistv5nvd
CVE-2019-1862HIGHCVSS 7.2v3.2.0JA2019-05-13
CVE-2019-1862 [HIGH] CWE-20 CVE-2019-1862: A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an aut A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid administrat
cvelistv5nvd
CVE-2019-1753HIGHCVSS 8.8v3.6.10Ev16.1.1+36 more2019-03-28
CVE-2019-1753 [HIGH] CWE-20 CVE-2019-1753: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by su
cvelistv5nvd
CVE-2019-1741HIGHCVSS 7.5v3.2.0JAv16.6.1+12 more2019-03-28
CVE-2019-1741 [HIGH] CWE-20 CVE-2019-1741: A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software coul A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been fre
cvelistv5nvd
CVE-2019-1745HIGHCVSS 7.8v3.10.0Sv3.10.1S+153 more2019-03-28
CVE-2019-1745 [HIGH] CWE-78 CVE-2019-1745: A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbi A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input t
cvelistv5nvd
CVE-2019-1755HIGHCVSS 7.2v3.6.10Ev16.1.1+36 more2019-03-28
CVE-2019-1755 [HIGH] CWE-20 CVE-2019-1755: A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by su
cvelistv5nvd
CVE-2019-1743HIGHCVSS 8.8v16.2.1v16.2.2+29 more2019-03-28
CVE-2019-1743 [HIGH] CWE-20 CVE-2019-1743: A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remot A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the device. An exploit co
cvelistv5nvd
CVE-2019-1750HIGHCVSS 7.4v3.6.0Ev3.6.1E+40 more2019-03-28
CVE-2019-1750 [HIGH] CWE-20 CVE-2019-1750: A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload. The vulnerability is due to incomplete error handling when processing Cisco Discovery Protocol (CDP) packets used with the Easy Virtual Switching System. An
cvelistv5nvd
CVE-2019-1754HIGHCVSS 8.8v3.2.0JAv16.7.1+14 more2019-03-28
CVE-2019-1754 [HIGH] CWE-20 CVE-2019-1754: A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to improper validation of user privileges of web UI users. An attacker could exploit this vulnerability by submitting a maliciou
cvelistv5nvd
CVE-2019-1749HIGHCVSS 7.4v3.13.6aSv3.16.0aS+47 more2019-03-28
CVE-2019-1749 [HIGH] CWE-20 CVE-2019-1749: A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Ser A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the software insufficient
cvelistv5nvd
CVE-2019-1756HIGHCVSS 7.2v3.2.0JAv16.7.1+12 more2019-03-28
CVE-2019-1756 [HIGH] CWE-20 CVE-2019-1756: A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute co A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid administrator access to an affected device could exp
cvelistv5nvd
CVE-2019-1759MEDIUMCVSS 5.3v3.2.0JAv16.2.1+43 more2019-03-28
CVE-2019-1759 [MEDIUM] CWE-284 CVE-2019-1759: A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interf A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16
cvelistv5nvd