Cisco Ios Xe Software vulnerabilities
238 known vulnerabilities affecting cisco/cisco_ios_xe_software.
Total CVEs
238
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
6
Severity breakdown
CRITICAL10HIGH136MEDIUM92
Vulnerabilities
Page 4 of 12
CVE-2024-20433HIGHCVSS 7.5v3.7.0Sv3.7.1S+395 more2024-09-25
CVE-2024-20433 [HIGH] CWE-121 CVE-2024-20433: A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An
cvelistv5nvd
CVE-2024-20464HIGHCVSS 8.6v17.13.1v17.13.1a2024-09-25
CVE-2024-20464 [HIGH] CWE-20 CVE-2024-20464: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could a
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit this vulnerability by sending a cr
cvelistv5nvd
CVE-2024-20437HIGHCVSS 8.8v17.3.2v17.3.3+64 more2024-09-25
CVE-2024-20437 [HIGH] CWE-352 CVE-2024-20437: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauth
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device.
This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected devi
cvelistv5nvd
CVE-2024-20467HIGHCVSS 8.6v17.12.1v17.12.1a+1 more2024-09-25
CVE-2024-20467 [HIGH] CWE-399 CVE-2024-20467: A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Soft
A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper management of resources during fragment reassembly. An attacker could exploit this vulnerabili
cvelistv5nvd
CVE-2024-20434MEDIUMCVSS 4.3v16.6.1v16.6.2+89 more2024-09-25
CVE-2024-20434 [MEDIUM] CWE-190 CVE-2024-20434: A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device.
This vulnerability is due to improper handling of frames with VLAN tag information. An attacker could exploit this vulnerability by sending crafted frames to an affected de
cvelistv5nvd
CVE-2024-20414MEDIUMCVSS 6.5v3.2.0SGv3.2.1SG+429 more2024-09-25
CVE-2024-20414 [MEDIUM] CWE-285 CVE-2024-20414: A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI.
This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could e
cvelistv5nvd
CVE-2024-20313HIGHCVSS 7.4v17.5.1v17.5.1a+36 more2024-04-24
CVE-2024-20313 [HIGH] CWE-120 CVE-2024-20313: A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unaut
A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by a device. An attacker could exploi
cvelistv5nvd
CVE-2024-20310MEDIUMCVSS 6.1vN/A2024-04-03
CVE-2024-20310 [MEDIUM] CWE-23 CVE-2024-20310: A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Ser
A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authenticated user of the interface.
This vulnerability exists because the web-based management interface does not properly
cvelistv5nvd
CVE-2024-20259HIGHCVSS 8.6v17.1.1v17.1.1a+78 more2024-03-27
CVE-2024-20259 [HIGH] CWE-122 CVE-2024-20259: A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated
A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint analytics are enabled. An attacker cou
cvelistv5nvd
CVE-2024-20303HIGHCVSS 7.4v17.2.1v17.2.1r+66 more2024-03-27
CVE-2024-20303 [HIGH] CWE-459 CVE-2024-20303: A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LA
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition.
This vulnerability is due to improper management of mDNS client entries. An attacker could exploit this vulnerability by connecting to t
cvelistv5nvd
CVE-2024-20307HIGHCVSS 7.5v3.4.8SGv3.10.8S+216 more2024-03-27
CVE-2024-20307 [HIGH] CWE-121 CVE-2024-20307: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabili
cvelistv5nvd
CVE-2024-20312HIGHCVSS 7.4v3.7.0Sv3.7.1S+383 more2024-03-27
CVE-2024-20312 [HIGH] CWE-476 CVE-2024-20312: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Soft
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An atta
cvelistv5nvd
CVE-2024-20311HIGHCVSS 7.5v3.7.0Sv3.7.1S+316 more2024-03-27
CVE-2024-20311 [HIGH] CWE-674 CVE-2024-20311: A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to
cvelistv5nvd
CVE-2024-20308HIGHCVSS 7.5v3.7.0Sv3.7.1S+379 more2024-03-27
CVE-2024-20308 [HIGH] CWE-787 CVE-2024-20308: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabil
cvelistv5nvd
CVE-2024-20314HIGHCVSS 7.5v16.1.1v16.1.2+184 more2024-03-27
CVE-2024-20314 [HIGH] CWE-783 CVE-2024-20314: A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IO
A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of certai
cvelistv5nvd
CVE-2024-20306MEDIUMCVSS 6.7v17.10.1v17.10.1a+7 more2024-03-27
CVE-2024-20306 [MEDIUM] CWE-233 CVE-2024-20306: A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could
A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device.
This vulnerability is due to insuff
cvelistv5nvd
CVE-2024-20309MEDIUMCVSS 5.5v3.7.0Sv3.7.1S+341 more2024-03-27
CVE-2024-20309 [MEDIUM] CWE-828 CVE-2024-20309: A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow
A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding.
This vulnerability is due to the incorrect handling of specific ingress traffic when flow control hardware is enabled on the AUX port. An attacker could exploit
cvelistv5nvd
CVE-2024-20316MEDIUMCVSS 5.3v16.3.1v16.3.2+158 more2024-03-27
CVE-2024-20316 [MEDIUM] CWE-390 CVE-2024-20316: A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an u
A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access resources that should have been protected by a configured IPv4 access control list (ACL).
This vulnerability is due to improper handling of error conditions when a successfully authorized device administrator
cvelistv5nvd
CVE-2024-20324MEDIUMCVSS 5.5v16.10.1v16.10.1s+58 more2024-03-27
CVE-2024-20324 [MEDIUM] CWE-274 CVE-2024-20324: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, lo
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords.
This vulnerability is due to improper privilege checks. An attacker could exploit this vulnerability by using the show and show tech wireless CLI commands to access configuration d
cvelistv5nvd
CVE-2024-20278MEDIUMCVSS 6.5v17.6.1v17.6.2+41 more2024-03-27
CVE-2024-20278 [MEDIUM] CWE-184 CVE-2024-20278: A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote
A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF to an affected device. A success
cvelistv5nvd