cbcvebase.

Cisco Ios Xr Software vulnerabilities

114 known vulnerabilities affecting cisco/cisco_ios_xr_software.

Total CVEs
114
CISA KEV
4
actively exploited
Public exploits
0
Exploited in wild
5
Severity breakdown
CRITICAL5HIGH62MEDIUM47

Vulnerabilities

Page 5 of 6
CVE-2025-20145P4MEDIUMCVSS 5.8v6.5.3v6.5.2+59 more2025-03-12
CVE-2025-20145 [MEDIUM] CWE-264 CVE-2025-20145: A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability exists because certain packets are handled incorrectly when they are received on an ingress interface on one line card and destined out of an egres
nvd
CVE-2025-20177P4MEDIUMCVSS 6.7v7.0.1v7.0.0+65 more2025-03-12
CVE-2025-20177 [MEDIUM] CWE-274 CVE-2025-20177: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device. This vulnerability is due to incomplete
nvd
CVE-2025-20143P4MEDIUMCVSS 6.7v6.5.3v6.5.2+57 more2025-03-12
CVE-2025-20143 [MEDIUM] CWE-347 CVE-2025-20143: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device. This vulnerability is due to i
nvd
CVE-2025-20248P4MEDIUMCVSS 6.0v6.5.3v6.5.29+88 more2025-09-10
CVE-2025-20248 [MEDIUM] CWE-347 CVE-2025-20248: A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, l A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR Software image signature verification and load unsigned software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device. This vulnerability is du
nvd
CVE-2025-20159P4MEDIUMCVSS 5.3v6.6.1v6.5.3+72 more2025-09-10
CVE-2025-20159 [MEDIUM] CWE-284 CVE-2025-20159: A vulnerability in the management interface access control list (ACL) processing feature in Cisco IO A vulnerability in the management interface access control list (ACL) processing feature in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass configured ACLs for the SSH, NetConf, and gRPC features. This vulnerability exists because management interface ACLs have not been supported on Cisco IOS XR Software Packet I/O i
nvd
CVE-2024-20456P4MEDIUMCVSS 6.7v24.2.12024-07-10
CVE-2024-20456 [MEDIUM] CWE-732 CVE-2024-20456: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected device. This vulnerability is due
nvd
CVE-2021-34708P4MEDIUMCVSS 6.7vn/a2021-09-09
CVE-2021-34708 [MEDIUM] CWE-347 CVE-2021-34708: Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more informat
nvd
CVE-2023-20190P4MEDIUMCVSS 5.3v5.2.0v5.2.1+79 more2023-09-13
CVE-2023-20190 [MEDIUM] CWE-264 CVE-2023-20190: A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Softwar A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to incorrect destination address range encoding in the compression module of an ACL that is
nvd
CVE-2021-1244P4MEDIUMCVSS 6.7vn/a2021-02-04
CVE-2021-1244 [MEDIUM] CWE-347 CVE-2021-1244: Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when run Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these
nvd
CVE-2021-1136P4MEDIUMCVSS 6.7vn/a2021-02-04
CVE-2021-1136 [MEDIUM] CWE-347 CVE-2021-1136: Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when run Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these
nvd
CVE-2021-34709P4MEDIUMCVSS 6.4vn/a2021-09-09
CVE-2021-34709 [MEDIUM] CWE-347 CVE-2021-34709: Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more informat
nvd
CVE-2019-1842P4MEDIUMCVSS 5.4≥ unspecified, < 6.1.42019-06-05
CVE-2019-1842 [MEDIUM] CWE-285 CVE-2019-1842: A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could all A vulnerability in the Secure Shell (SSH) authentication function of Cisco IOS XR Software could allow an authenticated, remote attacker to successfully log in to an affected device using two distinct usernames. The vulnerability is due to a logic error that may occur when certain sequences of actions are processed during an SSH login event on the aff
nvd
CVE-2020-3120P4MEDIUMCVSS 6.5≥ unspecified, < 2.3.1.1732020-02-05
CVE-2020-3120 [MEDIUM] CWE-190 CVE-2020-3120: A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software proce
nvd
CVE-2023-20233P4MEDIUMCVSS 6.5v5.2.0v5.2.1+57 more2023-09-13
CVE-2023-20233 [MEDIUM] CWE-476 CVE-2023-20233: A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could al A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs). An attacker could exploit this vulnerability by
nvd
CVE-2019-1909P4MEDIUMCVSS 5.9≥ unspecified, < 6.4.22019-07-06
CVE-2019-1909 [MEDIUM] CWE-20 CVE-2019-1909: A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect processing of certain BGP update messages. An attacker could exploit this vulnerability by
nvd
CVE-2020-3190P4MEDIUMCVSS 5.8≥ unspecified, < n/a2020-03-04
CVE-2020-3190 [MEDIUM] CWE-400 CVE-2020-3190: A vulnerability in the IPsec packet processor of Cisco IOS XR Software could allow an unauthenticate A vulnerability in the IPsec packet processor of Cisco IOS XR Software could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition for IPsec sessions to an affected device. The vulnerability is due to improper handling of packets by the IPsec packet processor. An attacker could exploit this vulnerability by sending mali
nvd
CVE-2019-15998P4MEDIUMCVSS 5.3≥ unspecified, < n/a2019-11-26
CVE-2019-15998 [MEDIUM] CWE-284 CVE-2019-15998: A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR S A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device. The vulnerability is due to a missing check in the NETCONF over SSH access control list (ACL). An attac
nvd
CVE-2024-20343P4MEDIUMCVSS 5.5v6.5.3v6.6.1+64 more2024-09-11
CVE-2024-20343 [MEDIUM] CWE-284 CVE-2024-20343: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device. This vulnerability is due to incorrect validation of the arguments that are passed to a specific CLI command. A
nvd
CVE-2019-16018P4MEDIUMCVSS 6.5≥ unspecified, < n/a2020-01-26
CVE-2019-16018 [MEDIUM] CWE-399 CVE-2019-16018: A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functiona A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains crafted EVPN attributes. An attacker cou
nvd
CVE-2020-3364P4MEDIUMCVSS 5.3vn/a2020-06-18
CVE-2020-3364 [MEDIUM] CWE-284 CVE-2020-3364: A vulnerability in the access control list (ACL) functionality of the standby route processor manage A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the standby route processor management Gigabit Ethernet Management interface. The vulnerability is due to a logic error that
nvd
Cisco Ios Xr Software vulnerabilities | cvebase