cbcvebase.

Cisco Ios Xe Software vulnerabilities

236 known vulnerabilities affecting cisco/cisco_ios_xe_software.

Total CVEs
236
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
9
Severity breakdown
CRITICAL10HIGH135MEDIUM91

Vulnerabilities

Page 12 of 12
CVE-2026-20110P4MEDIUMCVSS 6.5v16.6.1v16.6.2+228 more2026-03-25
CVE-2026-20110 [MEDIUM] CWE-266 CVE-2026-20110: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with the start maintenance command. An attacker could exploit this vulnerability by accessing the management CLI of t
nvd
CVE-2021-1616P4MEDIUMCVSS 4.7vn/a2021-09-23
CVE-2021-1616 [MEDIUM] CWE-693 CVE-2021-1616: A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG. This vulnerability is due to insufficient data validation of traffic that is traversing the ALG. An attacker could exploit this vulnerability by s
nvd
CVE-2020-3516P4MEDIUMCVSS 4.3vn/a2020-09-24
CVE-2020-3516 [MEDIUM] CWE-20 CVE-2020-3516: A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticat A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A su
nvd
CVE-2020-3428P4MEDIUMCVSS 6.5vn/a2020-09-24
CVE-2020-3428 [MEDIUM] CWE-20 CVE-2020-3428: A vulnerability in the WLAN Local Profiling feature of Cisco IOS XE Wireless Controller Software for A vulnerability in the WLAN Local Profiling feature of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect parsing of HTTP packets while performing HTTP-based endpoint devic
nvd
CVE-2018-0480P4MEDIUMCVSS 6.1vn/a2018-10-05
CVE-2018-0480 [MEDIUM] CWE-362 CVE-2018-0480: A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthent A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the so
nvd
CVE-2025-20214P4MEDIUMCVSS 4.3v17.11.1v17.11.1a+12 more2025-05-07
CVE-2025-20214 [MEDIUM] CWE-639 CVE-2025-20214: A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software c A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a subtle change in inner API call behavior causes results to be filtered incorrectly. An attacker c
nvd
CVE-2026-20112P4MEDIUMCVSS 4.8v16.6.1v16.6.2+224 more2026-03-25
CVE-2026-20112 [MEDIUM] CWE-79 CVE-2026-20112: A vulnerability in the web-based Cisco IOx application hosting environment management interface of C A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of
nvd
CVE-2025-20195P4MEDIUMCVSS 4.3v16.1.1v16.1.2+208 more2025-05-07
CVE-2025-20195 [MEDIUM] CWE-352 CVE-2025-20195: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauth A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a CSRF attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could expl
nvd
CVE-2024-20309P4MEDIUMCVSS 5.5v3.7.0Sv3.7.1S+341 more2024-03-27
CVE-2024-20309 [MEDIUM] CWE-828 CVE-2024-20309: A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This vulnerability is due to the incorrect handling of specific ingress traffic when flow control hardware is enabled on the AUX port. An attacker could exploit
nvd
CVE-2021-1436P4MEDIUMCVSS 4.4vn/a2021-03-24
CVE-2021-1436 [MEDIUM] CWE-22 CVE-2021-1436: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request
nvd
CVE-2020-3418P4MEDIUMCVSS 4.7vn/a2020-09-24
CVE-2020-3418 [MEDIUM] CWE-284 CVE-2020-3418: A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers could allow an unauthenticated, adjacent attacker to send ICMPv6 traffic prior to the client being placed into RUN state. The vulnerability is due to an incomplete access control list (ACL) being applied prior to RUN state. An attacker could exploit this
nvd
CVE-2021-1356P4MEDIUMCVSS 4.3vn/a2021-03-24
CVE-2021-1356 [MEDIUM] CWE-20 CVE-2021-1356: Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient error handling in the web UI. An attac
nvd
CVE-2021-1220P4MEDIUMCVSS 4.3vn/a2021-03-24
CVE-2021-1220 [MEDIUM] CWE-20 CVE-2021-1220: Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient error handling in the web UI. An attac
nvd
CVE-2024-20434P4MEDIUMCVSS 4.3v16.6.1v16.6.2+89 more2024-09-25
CVE-2024-20434 [MEDIUM] CWE-190 CVE-2024-20434: A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device. This vulnerability is due to improper handling of frames with VLAN tag information. An attacker could exploit this vulnerability by sending crafted frames to an affected de
nvd
CVE-2021-1374P4MEDIUMCVSS 4.8vn/a2021-03-24
CVE-2021-1374 [MEDIUM] CWE-79 CVE-2021-1374: A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software f A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software for the Catalyst 9000 Family of switches could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the web-based management interface of an affected device. The vulnerability is due to insufficien
nvd
CVE-2022-20864P4MEDIUMCVSS 4.6vn/a2022-10-10
CVE-2022-20864 [MEDIUM] CWE-538 CVE-2022-20864: A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Softwa A vulnerability in the password-recovery disable feature of Cisco IOS XE ROM Monitor (ROMMON) Software for Cisco Catalyst Switches could allow an unauthenticated, local attacker to recover the configuration or reset the enable password. This vulnerability is due to a problem with the file and boot variable permissions in ROMMON. An attacker could ex
nvd