Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
28
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 13 of 26
CVE-2019-12663HIGHCVSS 8.6v16.6.4v16.12.12019-09-25
CVE-2019-12663 [HIGH] CWE-20 CVE-2019-12663: A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of attributes in RADIUS messages. An attacke
nvd
CVE-2019-12646HIGHCVSS 7.5v15.4\(3\)sv15.5\(3\)s+11 more2019-09-25
CVE-2019-12646 [HIGH] CWE-399 CVE-2019-12646: A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Applicati A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected devi
nvd
CVE-2019-12647HIGHCVSS 7.5vfuji-16.7.1vfuji-16.8.12019-09-25
CVE-2019-12647 [HIGH] CWE-476 CVE-2019-12647: A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauth A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability exists because the affected software incorrectly handles memory structures, leading to a NULL pointer dereference. An attacker could exploit this vulnerability by openin
nvd
CVE-2019-12650HIGHCVSS 8.8v16.6.5v17.1.12019-09-25
CVE-2019-12650 [HIGH] CWE-77 CVE-2019-12650: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-12664HIGHCVSS 7.5v16.6.42019-09-25
CVE-2019-12664 [HIGH] CWE-200 CVE-2019-12664: A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Ci A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to successful PPP authentication. The vulnerability is due to insufficient validation of the state of
nvd
CVE-2019-12659HIGHCVSS 7.5v16.10.12019-09-25
CVE-2019-12659 [HIGH] CWE-399 CVE-2019-12659: A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, rem A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash. The vulnerability is due to a logical error in the logging mechanism. An attacker could exploit this vulnerability by generating a high amount of long-lived connections to the HTTP service on the device. A
nvd
CVE-2019-12653HIGHCVSS 7.5v16.9v16.10.12019-09-25
CVE-2019-12653 [HIGH] CWE-20 CVE-2019-12653: A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthen A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsing of Raw Socket Transport payloads. An attacker could exploit this vulnerability by establish
nvd
CVE-2019-12671HIGHCVSS 7.8v16.11.12019-09-25
CVE-2019-12671 [HIGH] CWE-285 CVE-2019-12671: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on an affected device and execute commands on the underlying operating system (OS). The vulnerability is due to insufficient enforcement of the consent token in authorizing shell access. An attacker could exploit this vulnerability by a
nvd
CVE-2019-12658HIGHCVSS 7.5v16.6.1v16.8.12019-09-25
CVE-2019-12658 [HIGH] CWE-400 CVE-2019-12658: A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an u A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesystem resources on an affected device and cause a denial of service (DoS) condition. The vulnerability is due to ineffective management of the underlying filesystem resources. An attacker could exploit thi
nvd
CVE-2019-12662MEDIUMCVSS 6.7v16.8.12019-09-25
CVE-2019-12662 [MEDIUM] CWE-347 CVE-2019-12662: A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, loca A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Op
nvd
CVE-2019-12649MEDIUMCVSS 6.7v16.8\(1\)2019-09-25
CVE-2019-12649 [MEDIUM] CWE-347 CVE-2019-12649: A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authentica A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability exists because, under certain circumstances, an affected device can be configured to not verify the digital signat
nvd
CVE-2019-12666MEDIUMCVSS 6.7≥ 16.4, < 16.6.5≥ 16.7, < 16.9.3+1 more2019-09-25
CVE-2019-12666 [MEDIUM] CWE-22 CVE-2019-12666: A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local atta A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain commands. An attacker could exploit this vulnerability by first accessing the Guest Shell and
nvd
CVE-2019-12668MEDIUMCVSS 4.8≥ 16.1.1, < 16.3.8≥ 16.4.1, < 16.6.5+8 more2019-09-25
CVE-2019-12668 [MEDIUM] CWE-79 CVE-2019-12668: A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an auth A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software using the banner parameter. The vulnerability is due to insufficient input validation of the banner parameters
nvd
CVE-2019-12667MEDIUMCVSS 4.8≥ 16.1.1, < 16.6.5≥ 16.7.1, < 16.9.22019-09-25
CVE-2019-12667 [MEDIUM] CWE-79 CVE-2019-12667: A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, rem A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affec
nvd
CVE-2019-12660MEDIUMCVSS 5.5≥ 16.1.12019-09-25
CVE-2019-12660 [MEDIUM] CWE-668 CVE-2019-12660: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authentica
nvd
CVE-2019-12661MEDIUMCVSS 6.7v15.3\(3\)sv15.4\(2\)s+5 more2019-09-25
CVE-2019-12661 [MEDIUM] CWE-77 CVE-2019-12661: A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software coul A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific VMAN CLI command on th
nvd
CVE-2019-12643CRITICALCVSS 10.0v15.5\(3\)s3.16v16.6.52019-08-28
CVE-2019-12643 [CRITICAL] CWE-287 CVE-2019-12643: A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allo A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that manages the REST API authentication service. An attacker could exploi
nvd
CVE-2019-12624HIGHCVSS 8.8PoC≥ 3.0.xe, ≤ 3.11.xe2019-08-21
CVE-2019-12624 [HIGH] CWE-352 CVE-2019-12624: A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Contro A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management
nvd
CVE-2019-1904HIGHCVSS 8.8v16.1.3v16.2.1+1 more2019-06-21
CVE-2019-1904 [HIGH] CWE-352 CVE-2019-1904: A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a use
nvd
CVE-2019-1862HIGHCVSS 7.2v16.3.72019-05-13
CVE-2019-1862 [HIGH] CWE-20 CVE-2019-1862: A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an aut A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid administrat
nvd