cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 11 of 26
CVE-2019-12659P3HIGHCVSS 7.5v16.10.12019-09-25
CVE-2019-12659 [HIGH] CWE-399 CVE-2019-12659: A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, rem A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. The vulnerability is due to a logical error in the logging mechanism. An attacker could exploit this vulnerability by generating a high amount of long-lived connections to the HTTP service on the device. A
nvd
CVE-2021-1446P3HIGHCVSS 7.5v3.7.0bsv3.7.0s+263 more2021-03-24
CVE-2021-1446 [HIGH] CWE-754 CVE-2021-1446: A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Tra A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a logic error that occurs when an affected device inspects certain DNS packets. An attacker could ex
nvd
CVE-2021-34768P3HIGHCVSS 7.5v3.15.1xbsv3.15.2xbs+5 more2021-09-23
CVE-2021-34768 [HIGH] CWE-415 CVE-2021-34768: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient va
nvd
CVE-2021-34769P3HIGHCVSS 7.5v3.15.1xbsv3.15.2xbs+5 more2021-09-23
CVE-2021-34769 [HIGH] CWE-415 CVE-2021-34769: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. These vulnerabilities are due to insufficient va
nvd
CVE-2020-3403P3HIGHCVSS 7.8v17.2.12020-09-24
CVE-2020-3403 [HIGH] CWE-78 CVE-2020-3403: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating system that will execute with root privileges upon the next reboot of the device. The authenticated user must have privileged EXEC permissions on the device. The vulnerability is due to insufficient protection of
nvd
CVE-2019-12671P3HIGHCVSS 7.8v16.11.12019-09-25
CVE-2019-12671 [HIGH] CWE-285 CVE-2019-12671: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of the consent token in authorizing shell access. An attacker could exploit this vulnerability by a
nvd
CVE-2023-20080P3HIGHCVSS 7.5v3.3.0xov3.3.1xo+363 more2023-03-23
CVE-2023-20080 [HIGH] CWE-129 CVE-2023-20080: A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS X A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries. An attacker could exploit this vulnerability by sending crafted DHCPv6 me
nvd
CVE-2023-20029P3HIGHCVSS 7.8v17.7.1v17.8.12023-03-23
CVE-2023-20029 [HIGH] CWE-122 CVE-2023-20029: A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticat A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device. This vulnerability is due to insufficient memory protection in the Meraki onboarding feature of an affected device. An attacker could exploit this vulnerability by modifying the Mer
nvd
CVE-2023-20227P3HIGHCVSS 7.5v16.8.1v16.8.1a+94 more2023-09-27
CVE-2023-20227 [HIGH] CWE-388 CVE-2023-20227: A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allo A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packet
nvd
CVE-2021-1432P3HIGHCVSS 7.3v3.15.1xbsv3.15.2xbs+23 more2021-03-24
CVE-2021-1432 [HIGH] CWE-20 CVE-2021-1432: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected device as a low-privileged user to exploit this vulnerability. This vulnerability is due to insufficient validation of
nvd
CVE-2023-20066P3MEDIUMCVSS 6.5v16.12.3v17.3.2+1 more2023-03-23
CVE-2023-20066 [MEDIUM] CWE-23 CVE-2023-20066: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this vulnerability by sending a crafted requ
nvd
CVE-2016-6380P3HIGHCVSS 8.1v3.1.0sv3.1.0sg+112 more2016-10-05
CVE-2016-6380 [HIGH] CWE-20 CVE-2016-6380: The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 a The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.
nvd
CVE-2025-20190P3MEDIUMCVSS 6.5v17.6.8v17.9.6+5 more2025-05-07
CVE-2025-20190 [MEDIUM] CWE-284 CVE-2025-20190: A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software c A vulnerability in the lobby ambassador web interface of Cisco IOS XE Wireless Controller Software could allow an authenticated, remote attacker to remove arbitrary users that are defined on an affected device. This vulnerability is due to insufficient access control of actions executed by lobby ambassador users. An attacker could exploit this vulne
nvd
CVE-2019-12654P3HIGHCVSS 7.5v15.6\(1\)s4.2v16.3.8+1 more2019-09-25
CVE-2019-12654 [HIGH] CWE-476 CVE-2019-12654: A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Soft A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient sanity checks on an internal data structure. An attacker could exp
nvd
CVE-2021-34699P3HIGHCVSS 7.7v3.3.0sev3.3.0xo+317 more2021-09-23
CVE-2021-34699 [HIGH] CWE-435 CVE-2021-34699: A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an aut A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a particular CLI command to be run
nvd
CVE-2020-3422P3HIGHCVSS 7.5v16.9.32020-09-24
CVE-2020-3422 [HIGH] CWE-371 CVE-2020-3422: A vulnerability in the IP Service Level Agreement (SLA) responder feature of Cisco IOS XE Software c A vulnerability in the IP Service Level Agreement (SLA) responder feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the IP SLA responder to reuse an existing port, resulting in a denial of service (DoS) condition. The vulnerability exists because the IP SLA responder could consume a port that could be used by anot
nvd
CVE-2022-20856P3HIGHCVSS 7.5v17.3.4c2022-09-30
CVE-2022-20856 [HIGH] CWE-664 CVE-2022-20856: A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mob A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) Mobility messages in Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error and i
nvd
CVE-2021-1442P3HIGHCVSS 7.8v3.6.3ev3.6.4e+222 more2021-03-24
CVE-2021-1442 [HIGH] CWE-532 CVE-2021-1442: A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Softwa A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to the level of an Administrator user (level 15) on an affected device. The vulnerability is due to insufficient protection of sensitive information. An attacker with low privileges cou
nvd
CVE-2021-1392P3HIGHCVSS 7.8v3.3.0xov3.3.1xo+27 more2021-03-24
CVE-2021-1392 [HIGH] CWE-522 CVE-2021-1392: A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip securit
nvd
CVE-2022-20678P3HIGHCVSS 7.5v16.9.6v16.12.4+2 more2022-04-15
CVE-2022-20678 [HIGH] CWE-413 CVE-2022-20678: A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, re A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of craft
nvd