Cisco Ios Xe Software vulnerabilities
236 known vulnerabilities affecting cisco/cisco_ios_xe_software.
Total CVEs
236
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
9
Severity breakdown
CRITICAL10HIGH135MEDIUM91
Vulnerabilities
Page 3 of 12
CVE-2024-20467P3HIGHCVSS 8.6v17.12.1v17.12.1a+1 more2024-09-25
CVE-2024-20467 [HIGH] CWE-399 CVE-2024-20467: A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Soft
A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper management of resources during fragment reassembly. An attacker could exploit this vulnerabili
nvd
CVE-2024-20259P3HIGHCVSS 8.6v17.1.1v17.1.1a+78 more2024-03-27
CVE-2024-20259 [HIGH] CWE-122 CVE-2024-20259: A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint analytics are enabled. An attacker cou
nvd
CVE-2024-20464P3HIGHCVSS 8.6v17.13.1v17.13.1a2024-09-25
CVE-2024-20464 [HIGH] CWE-20 CVE-2024-20464: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could a
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit this vulnerability by sending a cr
nvd
CVE-2021-1443P3HIGHCVSS 7.2vn/a2021-03-24
CVE-2021-1443 [HIGH] CWE-77 CVE-2021-1443: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software improperly sanitizes values that are parsed from a specific configuration file. An attacker cou
nvd
CVE-2022-20683P3HIGHCVSS 8.6vn/a2022-04-15
CVE-2022-20683 [HIGH] CWE-124 CVE-2022-20683: A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software
A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient packet verification for traffic inspected
nvd
CVE-2020-3510P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3510 [HIGH] CWE-388 CVE-2020-3510: A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200
A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device. The vulnerability is due to insufficient error handling when parsing DNS requests. An attacker could ex
nvd
CVE-2020-3526P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3526 [HIGH] CWE-20 CVE-2020-3526: A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cB
A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to crash a device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a malformed COPS message to the device. A
nvd
CVE-2021-1611P3HIGHCVSS 8.6vn/a2021-09-23
CVE-2021-1611 [HIGH] CWE-399 CVE-2021-1611: A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE Wireless Controller S
A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9800 Family Wireless Controller, Embedded Wireless Controller, and Embedded Wireless on Catalyst 9000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affecte
nvd
CVE-2021-1615P3HIGHCVSS 8.6vn/a2021-09-23
CVE-2021-1615 [HIGH] CWE-410 CVE-2021-1615: A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) S
A vulnerability in the packet processing functionality of Cisco Embedded Wireless Controller (EWC) Software for Catalyst Access Points (APs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected AP. This vulnerability is due to insufficient buffer allocation. An attacker could exploit this vulnerabil
nvd
CVE-2024-20480P3HIGHCVSS 8.6v16.1.1v16.1.2+203 more2024-09-25
CVE-2024-20480 [HIGH] CWE-783 CVE-2024-20480: A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition that requires a manual reload to recover.
This vulnerability is due to impro
nvd
CVE-2025-20162P3HIGHCVSS 8.6v16.11.1v16.11.1a+91 more2025-05-07
CVE-2025-20162 [HIGH] CWE-400 CVE-2025-20162: A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauth
A vulnerability in the DHCP snooping security feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a full interface queue wedge, which could result in a denial of service (DoS) condition.
This vulnerability is due to improper handling of DHCP request packets. An attacker could exploit this vulnerability by sending
nvd
CVE-2019-1755P3HIGHCVSS 7.2v3.6.10Ev16.1.1+36 more2019-03-28
CVE-2019-1755 [HIGH] CWE-20 CVE-2019-1755: A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could
A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by su
nvd
CVE-2019-12663P3HIGHCVSS 8.6≥ unspecified, < n/a2019-09-25
CVE-2019-12663 [HIGH] CWE-20 CVE-2019-12663: A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of
A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of attributes in RADIUS messages. An attacke
nvd
CVE-2020-3407P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3407 [HIGH] CWE-476 CVE-2020-3407: A vulnerability in the RESTCONF and NETCONF-YANG access control list (ACL) function of Cisco IOS XE
A vulnerability in the RESTCONF and NETCONF-YANG access control list (ACL) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of the ACL that is tied to the RESTCONF or NETCONF-YANG feature. An attacker could exploit this vulnerability by access
nvd
CVE-2020-3359P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3359 [HIGH] CWE-20 CVE-2020-3359: A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800
A vulnerability in the multicast DNS (mDNS) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper validation of mDNS packets. An attacker could exploit this vulnerability by sending a crafted mD
nvd
CVE-2019-1904P3HIGHCVSS 8.8≥ unspecified, < 16.4.12019-06-21
CVE-2019-1904 [HIGH] CWE-352 CVE-2019-1904: A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a use
nvd
CVE-2020-3399P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3399 [HIGH] CWE-126 CVE-2020-3399: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processi
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insufficient input validation d
nvd
CVE-2021-1624P3HIGHCVSS 8.6vn/a2021-09-23
CVE-2021-1624 [HIGH] CWE-399 CVE-2021-1624: A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Softw
A vulnerability in the Rate Limiting Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization in the Cisco QuantumFlow Processor of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to mishandling of the rate limiting fea
nvd
CVE-2022-20682P3HIGHCVSS 8.6vn/a2022-04-15
CVE-2022-20682 [HIGH] CWE-690 CVE-2022-20682: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processi
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to inadequate input validation of
nvd
CVE-2021-1565P3HIGHCVSS 8.6vn/a2021-09-23
CVE-2021-1565 [HIGH] CWE-415 CVE-2021-1565: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol
Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient vali
nvd