Cisco Ios Xr Software vulnerabilities
107 known vulnerabilities affecting cisco/cisco_ios_xr_software.
Total CVEs
107
CISA KEV
4
actively exploited
Public exploits
0
Exploited in wild
5
Severity breakdown
CRITICAL3HIGH57MEDIUM47
Vulnerabilities
Page 1 of 6
CVE-2020-3118P1HIGHCVSS 8.8KEV≥ unspecified, < 6.6.32020-02-05
CVE-2020-3118 [HIGH] CWE-134 CVE-2020-3118: A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit t
nvd
CVE-2022-20821P1MEDIUMCVSS 6.5KEVvn/a2022-05-26
CVE-2022-20821 [MEDIUM] CWE-200 CVE-2022-20821: A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, rem
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to t
nvd
CVE-2020-3566P1HIGHCVSS 8.6KEVvn/a2020-08-29
CVE-2020-3566 [HIGH] CWE-400 CVE-2020-3566: A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR So
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnera
nvd
CVE-2020-3569P1HIGHCVSS 8.6KEVvn/a2020-09-23
CVE-2020-3569 [HIGH] CWE-400 CVE-2020-3569: Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other p
nvd
CVE-2025-20363P1CRITICALCVSS 9.0Exploitedv6.5.1v6.5.2+11 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
nvd
CVE-2020-3284P2CRITICALCVSS 9.8vn/a2020-11-06
CVE-2020-3284 [CRITICAL] CWE-284 CVE-2020-3284: A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-
A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device. The PXE boot loader is part of the BIOS and runs over the management interface of hardware platforms that are runn
nvd
CVE-2019-1710P2CRITICALCVSS 9.8≥ unspecified, < 6.5.3≥ unspecified, < 7.0.12019-04-17
CVE-2019-1710 [CRITICAL] CWE-20 CVE-2019-1710: A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services R
A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to access internal applications running on the sysadmin VM. The vulnerability is due to incorrect isolation of the secondary management interface from internal
nvd
CVE-2024-20381P2HIGHCVSS 8.8v6.5.3v6.5.29+86 more2024-09-11
CVE-2024-20381 [HIGH] CWE-285 CVE-2024-20381: A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) a
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.
This
nvd
CVE-2026-20040P3HIGHCVSS 8.8v6.5.3v6.5.29+114 more2026-03-11
CVE-2026-20040 [HIGH] CWE-78 CVE-2026-20040: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could
nvd
CVE-2022-20655P3HIGHCVSS 8.8vN/A2024-11-15
CVE-2022-20655 [HIGH] CWE-78 CVE-2022-20655: A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an au
A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack.
The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vulnerability by injecting commands during the execution of
nvd
CVE-2025-20138P3HIGHCVSS 8.8v6.5.3v6.5.29+88 more2025-03-12
CVE-2025-20138 [HIGH] CWE-78 CVE-2025-20138: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could
nvd
CVE-2019-1686P3HIGHCVSS 8.6≥ unspecified, < 6.5.2≥ unspecified, < 6.6.12019-04-17
CVE-2019-1686 [HIGH] CWE-284 CVE-2019-1686: A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 900
A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. The vulnerability is due to incorrect processing of the ACL applied to an interface of an affecte
nvd
CVE-2021-34718P3HIGHCVSS 8.1vn/a2021-09-09
CVE-2021-34718 [HIGH] CWE-88 CVE-2021-34718: A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, rem
A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplied by the user for a specific file transfer method. An attacker with lower-level privileges cou
nvd
CVE-2024-20483P3HIGHCVSS 7.2v24.1.1v24.2.1+3 more2024-09-11
CVE-2024-20483 [HIGH] CWE-78 CVE-2024-20483: Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container o
Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the PON Manager MongoDB instance to perform command injection attacks on the P
nvd
CVE-2020-26070P3HIGHCVSS 8.6vn/a2020-11-12
CVE-2020-26070 [HIGH] CWE-404 CVE-2020-26070: A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 900
A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource allocation when an affected device processes network
nvd
CVE-2020-3217P3HIGHCVSS 8.8vn/a2020-06-03
CVE-2020-3217 [HIGH] CWE-20 CVE-2020-3217: A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Sof
A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insuff
nvd
CVE-2026-20046P3HIGHCVSS 8.8v6.6.1v6.5.3+55 more2026-03-11
CVE-2026-20046 [HIGH] CWE-264 CVE-2026-20046: A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could a
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device.
This vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker with a low-privileged
nvd
CVE-2025-20115P3HIGHCVSS 8.6v6.5.3v6.5.29+91 more2025-03-12
CVE-2025-20115 [HIGH] CWE-120 CVE-2025-20115: A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomo
nvd
CVE-2025-20142P3HIGHCVSS 8.6v7.1.15v7.1.2+32 more2025-03-12
CVE-2025-20142 [HIGH] CWE-20 CVE-2025-20142: A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy fe
A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset,
nvd
CVE-2025-20154P3HIGHCVSS 8.6v6.5.3v6.5.29+90 more2025-05-07
CVE-2025-20154 [HIGH] CWE-20 CVE-2025-20154: A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Softw
A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could cause the ipsla_ippm_server proces
nvd
1 / 6Next →