Cisco Ios Xe Software vulnerabilities
236 known vulnerabilities affecting cisco/cisco_ios_xe_software.
Total CVEs
236
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
9
Severity breakdown
CRITICAL10HIGH135MEDIUM91
Vulnerabilities
Page 5 of 12
CVE-2025-20175P3HIGHCVSS 7.7v3.2.0SGv3.2.1SG+452 more2025-02-05
CVE-2025-20175 [HIGH] CWE-805 CVE-2025-20175: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2022-20681P3HIGHCVSS 7.8vn/a2022-04-15
CVE-2022-20681 [HIGH] CWE-266 CVE-2022-20681: A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisc
A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected device. This vulnerability is due to insufficient validation of user privileges after the user executes certain CLI
nvd
CVE-2023-20065P3HIGHCVSS 7.8v16.4.1v16.4.2+48 more2023-03-23
CVE-2023-20065 [HIGH] CWE-284 CVE-2023-20065: A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Ci
nvd
CVE-2018-15372P3HIGHCVSS 8.1vn/a2018-10-05
CVE-2018-15372 [HIGH] CWE-284 CVE-2018-15372: A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport
A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic through a Layer 3 interface of an affected device. The vulnerability is due to a logic error in
nvd
CVE-2020-3393P3HIGHCVSS 7.8vn/a2020-09-24
CVE-2020-3393 [HIGH] CWE-269 CVE-2020-3393: A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authent
A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. The attacker could execute IOS XE commands outside the application-hosting subsystem Docker container as well as on the underlying Linux operating system. These commands could be
nvd
CVE-2023-20035P3HIGHCVSS 7.8vn/a2023-03-23
CVE-2023-20035 [HIGH] CWE-146 CVE-2023-20035: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI. An attacker with privileges to run commands could exploit this vulnerability by first authenticating to an affected
nvd
CVE-2025-20312P3HIGHCVSS 7.7v17.2.1v17.2.1r+124 more2025-09-24
CVE-2025-20312 [HIGH] CWE-835 CVE-2025-20312: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper error handling when parsing a specific SNMP request. An attacker could exploit this vulnerability by s
nvd
CVE-2026-20125P3HIGHCVSS 7.7v3.5.0Ev3.5.1E+155 more2026-03-25
CVE-2026-20125 [HIGH] CWE-228 CVE-2026-20125: A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3
A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this
nvd
CVE-2024-20307P3HIGHCVSS 7.5v3.4.8SGv3.10.8S+216 more2024-03-27
CVE-2024-20307 [HIGH] CWE-121 CVE-2024-20307: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabili
nvd
CVE-2024-20433P3HIGHCVSS 7.5v3.7.0Sv3.7.1S+395 more2024-09-25
CVE-2024-20433 [HIGH] CWE-121 CVE-2024-20433: A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An
nvd
CVE-2024-20436P3HIGHCVSS 7.5v3.9.1Sv3.9.2S+199 more2024-09-25
CVE-2024-20436 [HIGH] CWE-476 CVE-2024-20436: A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service featu
A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulner
nvd
CVE-2024-20311P3HIGHCVSS 7.5v3.7.0Sv3.7.1S+316 more2024-03-27
CVE-2024-20311 [HIGH] CWE-674 CVE-2024-20311: A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to
nvd
CVE-2024-20308P3HIGHCVSS 7.5v3.7.0Sv3.7.1S+379 more2024-03-27
CVE-2024-20308 [HIGH] CWE-787 CVE-2024-20308: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabil
nvd
CVE-2019-1741P3HIGHCVSS 7.5v3.2.0JAv16.6.1+12 more2019-03-28
CVE-2019-1741 [HIGH] CWE-20 CVE-2019-1741: A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software coul
A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been fre
nvd
CVE-2019-12653P3HIGHCVSS 7.5≥ unspecified, < n/a2019-09-25
CVE-2019-12653 [HIGH] CWE-20 CVE-2019-12653: A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthen
A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsing of Raw Socket Transport payloads. An attacker could exploit this vulnerability by establish
nvd
CVE-2019-12646P3HIGHCVSS 7.5≥ unspecified, < 3.2.11aSG2019-09-25
CVE-2019-12646 [HIGH] CWE-399 CVE-2019-12646: A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Applicati
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected devi
nvd
CVE-2020-3421P3HIGHCVSS 7.5vn/a2020-09-24
CVE-2020-3421 [HIGH] CWE-754 CVE-2020-3421: Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sen
nvd
CVE-2022-20679P3HIGHCVSS 7.7vn/a2022-04-15
CVE-2022-20679 [HIGH] CWE-20 CVE-2022-20679: A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthentica
A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to buffer exhaustion that occurs while traffic on a configured IPsec tunnel is being processed. An attacker could expl
nvd
CVE-2021-1431P3HIGHCVSS 7.5vn/a2021-03-24
CVE-2021-1431 [HIGH] CWE-20 CVE-2021-1431: A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticate
A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending crafted traffic to an affected d
nvd
CVE-2019-1745P3HIGHCVSS 7.8v3.10.0Sv3.10.1S+153 more2019-03-28
CVE-2019-1745 [HIGH] CWE-78 CVE-2019-1745: A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbi
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input t
nvd