Cisco Ios Xr Software vulnerabilities
107 known vulnerabilities affecting cisco/cisco_ios_xr_software.
Total CVEs
107
CISA KEV
4
actively exploited
Public exploits
0
Exploited in wild
5
Severity breakdown
CRITICAL3HIGH57MEDIUM47
Vulnerabilities
Page 6 of 6
CVE-2021-34771P4MEDIUMCVSS 5.5vn/a2021-09-09
CVE-2021-34771 [MEDIUM] CWE-201 CVE-2021-34771: A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to vie
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow. This vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by running a specific command. A successful
nvd
CVE-2022-20846P4MEDIUMCVSS 4.3v6.5.3v6.5.29+58 more2024-11-15
CVE-2022-20846 [MEDIUM] CWE-120 CVE-2022-20846: A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software c
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload on an affected device.
This vulnerability is due to a heap buffer overflow in certain Cisco Discovery Protocol messages. An attacker could exploit this vuln
nvd
CVE-2021-1128P4MEDIUMCVSS 5.5vn/a2021-02-04
CVE-2021-1128 [MEDIUM] CWE-201 CVE-2021-1128: A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attac
A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attacker to view more information than their privileges allow. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific command at the co
nvd
CVE-2024-20319P4MEDIUMCVSS 4.3v5.2.0v5.2.1+91 more2024-03-13
CVE-2024-20319 [MEDIUM] CWE-284 CVE-2024-20319: A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated,
A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of an affected device.
This vulnerability is due to incorrect UDP forwarding programming when using SNMP with manag
nvd
CVE-2023-20064P4MEDIUMCVSS 4.6vn/a2023-03-09
CVE-2023-20064 [MEDIUM] CWE-862 CVE-2023-20064: A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unau
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line. This vulnerability is due to the inclusion of unnecessary commands within the GRUB environment that allow sensitive
nvd
CVE-2022-20845P4MEDIUMCVSS 6.0v6.5.29v6.5.26+4 more2024-11-15
CVE-2022-20845 [MEDIUM] CWE-789 CVE-2022-20845: A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series could
A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series could allow an authenticated, local attacker to cause a memory leak in the TL1 process.
This vulnerability is due to TL1 not freeing memory under some conditions. An attacker could exploit this vulnerability by connecting to the device and issuing TL1 commands
nvd
CVE-2020-3449P4MEDIUMCVSS 4.3vn/a2020-08-17
CVE-2020-3449 [MEDIUM] CWE-754 CVE-2020-3449: A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Softwa
A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent authorized users from monitoring the BGP status and cause the BGP process to stop processing new updates, resulting in a denial of service (DOS) condition. The vulnerability is due to an inco
nvd
← Previous6 / 6