Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 12 of 26
CVE-2022-20848P3HIGHCVSS 7.5v17.6.1v17.6.3+1 more2022-09-30
CVE-2022-20848 [HIGH] CWE-399 CVE-2022-20848: A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless C
A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of UDP datagrams. An attacker could exploit this vulnerab
nvd
CVE-2022-20720P3HIGHCVSS 7.2v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20720 [HIGH] CWE-22 CVE-2022-20720: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) at
nvd
CVE-2024-20278P3MEDIUMCVSS 6.5v17.6.1v17.6.1a+41 more2024-03-27
CVE-2024-20278 [MEDIUM] CWE-184 CVE-2024-20278: A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote
A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input over NETCONF to an affected device. A success
nvd
CVE-2025-20193P3MEDIUMCVSS 6.5v17.3.1v17.3.1a+85 more2025-05-07
CVE-2025-20193 [MEDIUM] CWE-78 CVE-2025-20193: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authen
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device.r
This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based mana
nvd
CVE-2012-0382P3HIGHCVSS 7.5≥ 2.1.0, ≤ 2.6.2≥ 3.1.0s, < 3.4.1s+1 more2012-03-29
CVE-2012-0382 [HIGH] CWE-400 CVE-2012-0382: The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4,
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug I
nvd
CVE-2016-1384P3HIGHCVSS 7.5v3.2.0jav3.2.0s+152 more2016-04-20
CVE-2016-1384 [HIGH] CWE-264 CVE-2016-1384: The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attacker
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
nvd
CVE-2021-1623P3HIGHCVSS 7.7fixed in 17.6.1a2021-09-23
CVE-2021-1623 [HIGH] CWE-399 CVE-2021-1623: A vulnerability in the Simple Network Management Protocol (SNMP) punt handling function of Cisco cBR
A vulnerability in the Simple Network Management Protocol (SNMP) punt handling function of Cisco cBR-8 Converged Broadband Routers could allow an authenticated, remote attacker to overload a device punt path, resulting in a denial of service (DoS) condition. This vulnerability is due to the punt path being overwhelmed by large quantities of SNMP request
nvd
CVE-2022-20847P3HIGHCVSS 7.5v17.3.32022-09-30
CVE-2022-20847 [HIGH] CWE-399 CVE-2022-20847: A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software fo
A vulnerability in the DHCP processing functionality of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DHCP messages. An attacker could exploit this vulnerability by sending malic
nvd
CVE-2016-6382P3HIGHCVSS 7.5v3.6.0ev3.6.1e+60 more2016-10-05
CVE-2016-6382 [HIGH] CWE-399 CVE-2016-6382: Cisco IOS 15.2 through 15.6 and IOS XE 3.6 through 3.17 and 16.1 allow remote attackers to cause a d
Cisco IOS 15.2 through 15.6 and IOS XE 3.6 through 3.17 and 16.1 allow remote attackers to cause a denial of service (device restart) via a malformed IPv6 Protocol Independent Multicast (PIM) register packet, aka Bug ID CSCuy16399.
nvd
CVE-2015-0646P3HIGHCVSS 7.8v3.3xo.0v3.3xo.1+27 more2015-03-26
CVE-2015-0646 [HIGH] CWE-399 CVE-2015-0646: Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3
Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.3.xXO, 3.5.xE, 3.6.xE, 3.8.xS through 3.10.xS before 3.10.5S, and 3.11.xS and 3.12.xS before 3.12.3S allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted TCP packets over (1) IPv4 or (2) IPv6, aka
nvd
CVE-2015-6279P3HIGHCVSS 7.8v3.2se.0v3.2se.1+45 more2015-09-28
CVE-2015-6279 [HIGH] CWE-20 CVE-2015-6279: The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 1
The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE, 3.3XO, 3.4SG, 3.5E, and 3.6E before 3.6.3E; 3.7E before 3.7.2E; 3.9S and 3.10S before 3.10.6S; 3.11S before 3.11.4S; 3.12S and 3.13S before 3.13.3S; and 3.14S before 3.14.2S allows remote attackers to caus
nvd
CVE-2018-0476P3MEDIUMCVSS 5.9v15.5\(3\)s5.1v15.5\(3\)s6.1+1 more2018-10-05
CVE-2018-0476 [MEDIUM] CWE-399 CVE-2018-0476: A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Applicati
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of SIP packets in transit while NAT is performed on an affected device
nvd
CVE-2021-1620P3HIGHCVSS 7.7v3.8.0ev3.8.1e+275 more2021-09-23
CVE-2021-1620 [HIGH] CWE-563 CVE-2021-1620: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certai
nvd
CVE-2020-3232P3HIGHCVSS 7.7v3.16.0sv3.16.1as+55 more2020-06-03
CVE-2020-3232 [HIGH] CWE-19 CVE-2020-3232: A vulnerability in the Simple Network Management Protocol (SNMP) implementation in Cisco ASR 920 Ser
A vulnerability in the Simple Network Management Protocol (SNMP) implementation in Cisco ASR 920 Series Aggregation Services Router model ASR920-12SZ-IM could allow an authenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect handling of data that is returned for Cisco Discovery Protocol queries to SNMP. An attac
nvd
CVE-2016-6393P3HIGHCVSS 7.5≥ 2.1.0, ≤ 3.18.0v16.22016-10-05
CVE-2016-6393 [HIGH] CWE-399 CVE-2016-6393: The AAA service in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.1 through 3.18 and
The AAA service in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 2.1 through 3.18 and 16.2 allows remote attackers to cause a denial of service (device reload) via a failed SSH connection attempt that is mishandled during generation of an error-log message, aka Bug ID CSCuy87667.
nvd
CVE-2016-6384P3HIGHCVSS 7.5≥ 3.1, ≤ 3.17v16.22016-10-05
CVE-2016-6384 [HIGH] CWE-20 CVE-2016-6384: Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote
Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device reload) via crafted fields in an H.323 message, aka Bug ID CSCux04257.
nvd
CVE-2025-20338P3MEDIUMCVSS 6.7v3.5.0ev3.5.0sq+372 more2025-09-24
CVE-2025-20338 [MEDIUM] CWE-141 CVE-2025-20338: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker co
nvd
CVE-2015-6278P3HIGHCVSS 7.8v3.2se.0v3.2se.1+54 more2015-09-28
CVE-2015-6278 [HIGH] CWE-20 CVE-2015-6278: The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 1
The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE, 3.3XO, 3.4SG, 3.5E, and 3.6E before 3.6.3E; 3.7E before 3.7.2E; 3.9S and 3.10S before 3.10.6S; 3.11S before 3.11.4S; 3.12S and 3.13S before 3.13.3S; and 3.14S before 3.14.2S does not properly implement the
nvd
CVE-2012-0381P3HIGHCVSS 7.5≥ 2.1.0, ≤ 2.6.2≥ 3.1.0s, < 3.4.1s+1 more2012-03-29
CVE-2012-0381 [HIGH] CWE-310 CVE-2012-0381: The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x throu
The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.
nvd
CVE-2014-3354P3HIGHCVSS 7.8v2.1v2.1.0+122 more2014-09-25
CVE-2014-3354 [HIGH] CWE-20 CVE-2014-3354: Cisco IOS 12.0, 12.2, 12.4, 15.0, 15.1, 15.2, and 15.3 and IOS XE 2.x and 3.x before 3.7.4S; 3.2.xSE
Cisco IOS 12.0, 12.2, 12.4, 15.0, 15.1, 15.2, and 15.3 and IOS XE 2.x and 3.x before 3.7.4S; 3.2.xSE and 3.3.xSE before 3.3.2SE; 3.3.xSG and 3.4.xSG before 3.4.4SG; and 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S allow remote attackers to cause a denial of service (device reload) via malformed RSVP packets, aka Bug ID CSCui11547.
nvd