Cisco Ios Xr Software vulnerabilities
108 known vulnerabilities affecting cisco/cisco_ios_xr_software.
Total CVEs
108
CISA KEV
4
actively exploited
Public exploits
0
Exploited in wild
4
Severity breakdown
CRITICAL3HIGH57MEDIUM48
Vulnerabilities
Page 6 of 6
CVE-2019-1846HIGHCVSS 7.4≥ unspecified, < n/a2019-05-16
CVE-2019-1846 [HIGH] CWE-20 CVE-2019-1846: A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintena
A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to the
cvelistv5nvd
CVE-2019-1849MEDIUMCVSS 6.5≥ unspecified, < n/a2019-05-16
CVE-2019-1849 [MEDIUM] CWE-754 CVE-2019-1849: A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethern
A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a logic error that occurs when the affected softwar
cvelistv5nvd
CVE-2019-1710CRITICALCVSS 9.8≥ unspecified, < 6.5.3≥ unspecified, < 7.0.12019-04-17
CVE-2019-1710 [CRITICAL] CWE-20 CVE-2019-1710: A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services R
A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to access internal applications running on the sysadmin VM. The vulnerability is due to incorrect isolation of the secondary management interface from internal
cvelistv5nvd
CVE-2019-1712HIGHCVSS 7.5≥ unspecified, < 6.2.3≥ unspecified, < 6.3.2+2 more2019-04-17
CVE-2019-1712 [HIGH] CWE-20 CVE-2019-1712: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could a
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the PIM process to restart, resulting in a denial of service condition on an affected device. The vulnerability is due to the incorrect processing of crafted AutoRP packets. An attacker could exploit this v
cvelistv5nvd
CVE-2019-1711HIGHCVSS 7.5≥ unspecified, < 6.5.12019-04-17
CVE-2019-1711 [HIGH] CWE-20 CVE-2019-1711: A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow a
A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of gRPC requests. An attacker could exploit this vulnerability by repeatedly sending unauthenticated gRPC r
cvelistv5nvd
CVE-2019-1686HIGHCVSS 8.6≥ unspecified, < 6.5.2≥ unspecified, < 6.6.12019-04-17
CVE-2019-1686 [HIGH] CWE-284 CVE-2019-1686: A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 900
A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. The vulnerability is due to incorrect processing of the ACL applied to an interface of an affecte
cvelistv5nvd
CVE-2018-15428MEDIUMCVSS 6.8vn/a2018-10-05
CVE-2018-15428 [MEDIUM] CWE-20 CVE-2018-15428: A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR
A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP update messages. An attacker could exploit this vulnerability by sending BGP update
cvelistv5nvd
CVE-2017-6599MEDIUMCVSS 5.3vCisco IOS XR Software2017-04-07
CVE-2017-6599 [MEDIUM] CVE-2017-6599: A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to ca
A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash due to a system memory leak, resulting in a denial of service (DoS) condition. This vulnerability affects
cvelistv5
← Previous6 / 6