Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 10 of 26
CVE-2022-20718P3HIGHCVSS 7.2v16.3.1v16.3.1a+137 more2022-04-15
CVE-2022-20718 [HIGH] CWE-22 CVE-2022-20718: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) at
nvd
CVE-2022-20920P3HIGHCVSS 7.7v3.2.0sev3.2.1se+417 more2022-10-10
CVE-2022-20920 [HIGH] CWE-755 CVE-2022-20920: A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allo
A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affecte
nvd
CVE-2022-20723P3HIGHCVSS 7.2v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20723 [HIGH] CWE-22 CVE-2022-20723: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) at
nvd
CVE-2019-1745P3HIGHCVSS 7.8v3.6.10ev3.10.0s+153 more2019-03-28
CVE-2019-1745 [HIGH] CWE-78 CVE-2019-1745: A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbi
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input t
nvd
CVE-2020-3404P3HIGHCVSS 7.8v16.11.12020-09-24
CVE-2020-3404 [HIGH] CWE-863 CVE-2020-3404: A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow
A vulnerability in the persistent Telnet/Secure Shell (SSH) CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient enforcement of the consent token in authorizing shell
nvd
CVE-2022-20919P3HIGHCVSS 7.5v17.9.12022-09-30
CVE-2022-20919 [HIGH] CWE-248 CVE-2022-20919: A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sen
A vulnerability in the processing of malformed Common Industrial Protocol (CIP) packets that are sent to Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient input valid
nvd
CVE-2024-20314P3HIGHCVSS 7.5v16.1.1v16.1.2+184 more2024-03-27
CVE-2024-20314 [HIGH] CWE-783 CVE-2024-20314: A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IO
A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause high CPU utilization and stop all traffic processing, resulting in a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper handling of certai
nvd
CVE-2023-20226P3HIGHCVSS 7.5v17.7.1v17.7.1a+9 more2023-09-27
CVE-2023-20226 [HIGH] CWE-456 CVE-2023-20226: A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Ci
A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to the mishandling of a crafted packet stream through the
nvd
CVE-2023-20187P3HIGHCVSS 7.5v3.7.1sv3.7.2s+199 more2023-09-27
CVE-2023-20187 [HIGH] CWE-823 CVE-2023-20187: A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software fo
A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition.
This vulnerability is due to incorrect handling of certain IPv
nvd
CVE-2015-0635P3CRITICALCVSS 9.0v3.10s.0v3.10s.1+12 more2015-03-26
CVE-2015-0635 [CRITICAL] CWE-20 CVE-2015-0635: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of serv
nvd
CVE-2019-1752P3HIGHCVSS 7.5v3.8.0sv3.8.1s+127 more2019-03-28
CVE-2019-1752 [HIGH] CWE-20 CVE-2019-1752: A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of specific values in the Q.931 information elements. An attacker could exploit this vulnerability by calling the affected device with specifi
nvd
CVE-2017-3856P3HIGHCVSS 7.5v3.1.0sv3.1.0sg+196 more2017-03-22
CVE-2017-3856 [HIGH] CWE-399 CVE-2017-3856: A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenti
A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient resource handling by the affected software when the web user interface is under a high load. An attacker could exploit this vulnerability by sending a h
nvd
CVE-2020-3200P3HIGHCVSS 7.7v3.2.0sev3.2.1se+287 more2020-06-03
CVE-2020-3200 [HIGH] CWE-371 CVE-2020-3200: A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Softwar
A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. The vulnerability is due to an internal state not being represented correctly in the SSH state machine, which leads to an unexpected behavior. An attacker could exploit
nvd
CVE-2020-3235P3HIGHCVSS 7.7v3.2.0sgv3.2.1sg+66 more2020-06-03
CVE-2020-3235 [HIGH] CWE-118 CVE-2020-3235: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the software processes specific SNMP object
nvd
CVE-2019-12647P3HIGHCVSS 7.5vfuji-16.7.1vfuji-16.8.12019-09-25
CVE-2019-12647 [HIGH] CWE-476 CVE-2019-12647: A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauth
A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, leading to a NULL pointer dereference. An attacker could exploit this vulnerability by openin
nvd
CVE-2019-12657P3HIGHCVSS 7.5v16.3.62019-09-25
CVE-2019-12657 [HIGH] CWE-20 CVE-2019-12657: A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthentica
A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper validation of IPv6 packets through the UTD feature. An attacker could exploit this vulnerability by sending IPv6 traffic through an affected device that is c
nvd
CVE-2025-20200P3HIGHCVSS 8.2v3.2.0sev3.2.1se+408 more2025-05-07
CVE-2025-20200 [HIGH] CWE-754 CVE-2025-20200: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.
This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulne
nvd
CVE-2025-20197P3HIGHCVSS 8.2v3.7.0bsv3.7.0s+327 more2025-05-07
CVE-2025-20197 [HIGH] CWE-20 CVE-2025-20197: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.
This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulner
nvd
CVE-2025-20198P3HIGHCVSS 8.2v3.7.0ev3.7.1e+336 more2025-05-07
CVE-2025-20198 [HIGH] CWE-754 CVE-2025-20198: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.
This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulne
nvd
CVE-2025-20199P3HIGHCVSS 8.2v3.2.0sev3.2.1se+404 more2025-05-07
CVE-2025-20199 [HIGH] CVE-2025-20199: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device.
This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vulnerability
nvd