cbcvebase.

Cisco Ios Xe Software vulnerabilities

236 known vulnerabilities affecting cisco/cisco_ios_xe_software.

Total CVEs
236
CISA KEV
6
actively exploited
Public exploits
4
Exploited in wild
9
Severity breakdown
CRITICAL10HIGH135MEDIUM91

Vulnerabilities

Page 6 of 12
CVE-2020-3404P3HIGHCVSS 7.8vn/a2020-09-24
CVE-2020-3404 [HIGH] CWE-863 CVE-2020-3404: A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient enforcement of the consent token in authorizing shell
nvd
CVE-2024-20314P3HIGHCVSS 7.5v16.1.1v16.1.2+184 more2024-03-27
CVE-2024-20314 [HIGH] CWE-783 CVE-2024-20314: A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IO A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certai
nvd
CVE-2023-20226P3HIGHCVSS 7.5v17.7.1v17.7.1a+9 more2023-09-27
CVE-2023-20226 [HIGH] CWE-456 CVE-2023-20226: A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Ci A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the
nvd
CVE-2023-20187P3HIGHCVSS 7.5v3.7.1Sv3.7.2S+201 more2023-09-27
CVE-2023-20187 [HIGH] CWE-823 CVE-2023-20187: A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software fo A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv
nvd
CVE-2025-20200P3HIGHCVSS 8.2v3.7.0Sv3.7.1S+408 more2025-05-07
CVE-2025-20200 [HIGH] CWE-754 CVE-2025-20200: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulne
nvd
CVE-2025-20197P3HIGHCVSS 8.2v3.7.0Sv3.7.1S+327 more2025-05-07
CVE-2025-20197 [HIGH] CWE-20 CVE-2025-20197: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulner
nvd
CVE-2025-20198P3HIGHCVSS 8.2v3.13.0Sv3.13.1S+336 more2025-05-07
CVE-2025-20198 [HIGH] CWE-754 CVE-2025-20198: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulne
nvd
CVE-2025-20199P3HIGHCVSS 8.2v3.7.0Sv3.7.1S+404 more2025-05-07
CVE-2025-20199 [HIGH] CVE-2025-20199: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability
nvd
CVE-2021-1446P3HIGHCVSS 7.5vn/a2021-03-24
CVE-2021-1446 [HIGH] CWE-754 CVE-2021-1446: A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Tra A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a logic error that occurs when an affected device inspects certain DNS packets. An attacker could ex
nvd
CVE-2021-34768P3HIGHCVSS 7.5vn/a2021-09-23
CVE-2021-34768 [HIGH] CWE-415 CVE-2021-34768: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient va
nvd
CVE-2021-34769P3HIGHCVSS 7.5vn/a2021-09-23
CVE-2021-34769 [HIGH] CWE-415 CVE-2021-34769: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient va
nvd
CVE-2020-3403P3HIGHCVSS 7.8vn/a2020-09-24
CVE-2020-3403 [HIGH] CWE-78 CVE-2020-3403: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating system that will execute with root privileges upon the next reboot of the device. The authenticated user must have privileged EXEC permissions on the device. The vulnerability is due to insufficient protection of
nvd
CVE-2023-20029P3HIGHCVSS 7.8vn/a2023-03-23
CVE-2023-20029 [HIGH] CWE-122 CVE-2023-20029: A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticat A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device. This vulnerability is due to insufficient memory protection in the Meraki onboarding feature of an affected device. An attacker could exploit this vulnerability by modifying the Mer
nvd
CVE-2025-20192P3HIGHCVSS 7.7v3.13.0Sv3.13.1S+187 more2025-05-07
CVE-2025-20192 [HIGH] CWE-232 CVE-2025-20192: A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Softwa A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The attacker must have valid IKEv1 VPN credentials to exploit this vulnerability. This vulnerability is due to improper validation of IKEv1 phase 2 parameters
nvd
CVE-2023-20227P3HIGHCVSS 7.5v16.8.1v16.8.1a+95 more2023-09-27
CVE-2023-20227 [HIGH] CWE-388 CVE-2023-20227: A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allo A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packet
nvd
CVE-2021-1432P3HIGHCVSS 7.3vn/a2021-03-24
CVE-2021-1432 [HIGH] CWE-20 CVE-2021-1432: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability. This vulnerability is due to insufficient validation of
nvd
CVE-2023-20066P3MEDIUMCVSS 6.5vn/a2023-03-23
CVE-2023-20066 [MEDIUM] CWE-23 CVE-2023-20066: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this vulnerability by sending a crafted requ
nvd
CVE-2025-20190P3MEDIUMCVSS 6.5v17.6.8v17.9.6+5 more2025-05-07
CVE-2025-20190 [MEDIUM] CWE-284 CVE-2025-20190: A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software c A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient access control of actions executed by lobby ambassador users. An attacker could exploit this vulne
nvd
CVE-2020-3422P3HIGHCVSS 7.5vn/a2020-09-24
CVE-2020-3422 [HIGH] CWE-371 CVE-2020-3422: A vulnerability in the IP Service Level Agreement (SLA) responder feature of Cisco IOS XE Software c A vulnerability in the IP Service Level Agreement (SLA) responder feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the IP SLA responder to reuse an existing port, resulting in a denial of service (DoS) condition. The vulnerability exists because the IP SLA responder could consume a port that could be used by anot
nvd
CVE-2022-20856P3HIGHCVSS 7.5vn/a2022-09-30
CVE-2022-20856 [HIGH] CWE-664 CVE-2022-20856: A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mob A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error and i
nvd