Cisco Ios Xe Software vulnerabilities
236 known vulnerabilities affecting cisco/cisco_ios_xe_software.
Total CVEs
236
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
9
Severity breakdown
CRITICAL10HIGH135MEDIUM91
Vulnerabilities
Page 4 of 12
CVE-2023-20072P3HIGHCVSS 8.6vn/a2023-03-23
CVE-2023-20072 [HIGH] CWE-20 CVE-2023-20072: A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Softwa
A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of large fragmented tunnel protocol packets. One example of a t
nvd
CVE-2022-20837P3HIGHCVSS 8.6vn/a2022-10-10
CVE-2022-20837 [HIGH] CWE-754 CVE-2022-20837: A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Add
A vulnerability in the DNS application layer gateway (ALG) functionality that is used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a logic error that occurs when an affected device inspects certain TCP DNS packets. An at
nvd
CVE-2022-20870P3HIGHCVSS 8.6vn/a2022-10-10
CVE-2022-20870 [HIGH] CWE-130 CVE-2022-20870: A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Cat
A vulnerability in the egress MPLS packet processing function of Cisco IOS XE Software for Cisco Catalyst 3650, Catalyst 3850, and Catalyst 9000 Family Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient
nvd
CVE-2021-1373P3HIGHCVSS 8.6vn/a2021-03-24
CVE-2021-1373 [HIGH] CWE-126 CVE-2021-1373: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processi
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insuffi
nvd
CVE-2020-3509P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3509 [HIGH] CWE-388 CVE-2020-3509: A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broad
A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the supervisor to crash, which could result in a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when DHCP version 4 (DHCPv4) messages are par
nvd
CVE-2020-3480P3HIGHCVSS 8.6vn/a2020-09-24
CVE-2020-3480 [HIGH] CWE-754 CVE-2020-3480: Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sen
nvd
CVE-2021-34697P3HIGHCVSS 8.6vn/a2021-09-23
CVE-2021-34697 [HIGH] CWE-665 CVE-2021-34697: A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS
A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is due to incorrect programming of the half-opened connections limit, TCP SYN flood limit, or T
nvd
CVE-2023-20027P3HIGHCVSS 8.6vn/a2023-03-23
CVE-2023-20027 [HIGH] CWE-416 CVE-2023-20027: A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of
A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel
nvd
CVE-2023-20033P3HIGHCVSS 8.6v16.3.1v16.3.2+56 more2023-09-27
CVE-2023-20033 [HIGH] CWE-770 CVE-2023-20033: A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches c
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper resource management when processing traffic that is received on th
nvd
CVE-2019-12664P3HIGHCVSS 7.5≥ unspecified, < n/a2019-09-25
CVE-2019-12664 [HIGH] CWE-200 CVE-2019-12664: A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Ci
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to successful PPP authentication. The vulnerability is due to insufficient validation of the state of
nvd
CVE-2025-20172P3HIGHCVSS 7.7v3.7.0Sv3.7.1S+424 more2025-02-05
CVE-2025-20172 [HIGH] CWE-248 CVE-2025-20172: A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR
A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted S
nvd
CVE-2022-20693P3HIGHCVSS 7.2vn/a2022-04-15
CVE-2022-20693 [HIGH] CWE-74 CVE-2022-20693: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI API. A successful exploit could allow the a
nvd
CVE-2022-20851P3HIGHCVSS 7.2vn/a2022-09-30
CVE-2022-20851 [HIGH] CWE-77 CVE-2022-20851: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI API. A successful exploit could allow the a
nvd
CVE-2021-1622P3HIGHCVSS 8.6vn/a2021-09-23
CVE-2021-1622 [HIGH] CWE-833 CVE-2021-1622: A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Co
A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under cert
nvd
CVE-2025-20171P3HIGHCVSS 7.7v3.2.0SGv3.2.1SG+450 more2025-02-05
CVE-2025-20171 [HIGH] CWE-248 CVE-2025-20171: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20170P3HIGHCVSS 7.7v3.2.0SGv3.2.1SG+444 more2025-02-05
CVE-2025-20170 [HIGH] CWE-805 CVE-2025-20170: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20169P3HIGHCVSS 7.7v3.2.0SGv3.2.1SG+444 more2025-02-05
CVE-2025-20169 [HIGH] CWE-805 CVE-2025-20169: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20174P3HIGHCVSS 7.7v3.11.1Sv3.11.2S+257 more2025-02-05
CVE-2025-20174 [HIGH] CWE-805 CVE-2025-20174: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20176P3HIGHCVSS 7.7v3.3.0SEv3.3.1SE+378 more2025-02-05
CVE-2025-20176 [HIGH] CWE-248 CVE-2025-20176: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20173P3HIGHCVSS 7.7v3.2.0SGv3.2.1SG+448 more2025-02-05
CVE-2025-20173 [HIGH] CWE-248 CVE-2025-20173: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd