Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 14 of 26
CVE-2013-5545P3HIGHCVSS 7.8v3.9.0sv3.9.1s2013-10-31
CVE-2013-5545 [HIGH] CWE-20 CVE-2013-5545: The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote atta
The PPTP ALG implementation in Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending many PPTP packets over NAT, aka Bug ID CSCuh19936.
nvd
CVE-2016-6392P3HIGHCVSS 7.5v3.1.0sv3.1.1s+71 more2016-10-05
CVE-2016-6392 [HIGH] CWE-399 CVE-2016-6392: Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a de
Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.
nvd
CVE-2016-6378P3HIGHCVSS 7.5v3.1.3sv3.1.4as+81 more2016-10-05
CVE-2016-6378 [HIGH] CWE-399 CVE-2016-6378: Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of ser
Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets that require NAT, aka Bug ID CSCuw85853.
nvd
CVE-2021-34714P3HIGHCVSS 7.4≤ 8.4\(3.115\)≤ 7.0\(3\)i7\(9\)+3 more2021-09-23
CVE-2021-34714 [HIGH] CWE-20 CVE-2021-34714: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IO
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An att
nvd
CVE-2024-20312P3HIGHCVSS 7.4v3.2.0sev3.2.1se+383 more2024-03-27
CVE-2024-20312 [HIGH] CWE-476 CVE-2024-20312: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Soft
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An atta
nvd
CVE-2025-20189P3HIGHCVSS 7.4v3.16.0csv3.16.0s+264 more2025-05-07
CVE-2025-20189 [HIGH] CWE-762 CVE-2025-20189: A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR
A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition.
This vulnerability is due to improper memory management when Cisco IOS XE Software
nvd
CVE-2025-20202P3HIGHCVSS 7.4v16.10.1v16.10.1a+151 more2025-05-07
CVE-2025-20202 [HIGH] CWE-805 CVE-2025-20202: A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacen
A vulnerability in Cisco IOS XE Wireless Controller Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation of access point (AP) Cisco Discovery Protocol (CDP) neighbor reports when they are processed by the wireless contro
nvd
CVE-2009-2051P3HIGHCVSS 7.8≥ 2.5.0, ≤ 2.6.12009-08-27
CVE-2009-2051 [HIGH] CVE-2009-2051: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message t
nvd
CVE-2014-3327P3HIGHCVSS 7.8v3.2.00.xo.15.0\(2\)xov3.2.0xo+10 more2014-08-11
CVE-2014-3327 [HIGH] CWE-20 CVE-2014-3327: The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4
The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCup52101.
nvd
CVE-2012-0386P3HIGHCVSS 7.8v2.3v2.3.0+27 more2012-03-29
CVE-2012-0386 [HIGH] CWE-310 CVE-2012-0386: The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.
The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.
nvd
CVE-2014-3355P3HIGHCVSS 7.8v3.3\(.0\)xov3.6.0s+15 more2014-09-25
CVE-2014-3355 [HIGH] CWE-119 CVE-2014-3355: The metadata flow feature in Cisco IOS 15.1 through 15.3 and IOS XE 3.3.xXO before 3.3.1XO, 3.6.xS a
The metadata flow feature in Cisco IOS 15.1 through 15.3 and IOS XE 3.3.xXO before 3.3.1XO, 3.6.xS and 3.7.xS before 3.7.6S, and 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S allows remote attackers to cause a denial of service (device reload) via malformed RSVP packets, aka Bug ID CSCug75942.
nvd
CVE-2012-4623P3HIGHCVSS 7.8v2.1v2.1.0+43 more2012-09-27
CVE-2012-4623 [HIGH] CWE-20 CVE-2012-4623: The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.
The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723.
nvd
CVE-2016-6385P3HIGHCVSS 7.5v3.2.0jav3.2.0se+30 more2016-10-05
CVE-2016-6385 [HIGH] CWE-399 CVE-2016-6385: Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and I
Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.
nvd
CVE-2015-0636P3HIGHCVSS 7.8v3.10s.4v3.12s.0+4 more2015-03-26
CVE-2015-0636 [HIGH] CWE-20 CVE-2015-0636: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine, aka Bug ID CSCup62293.
nvd
CVE-2015-6272P3HIGHCVSS 7.8v2.1.0v2.1.1+6 more2015-08-31
CVE-2015-6272 [HIGH] CWE-399 CVE-2015-6272: Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway i
Cisco IOS XE 2.1.0 through 2.2.3 and 2.3.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted H.323 packet, aka Bug ID CSCsx35393, CSCsx07094, and CSCsw93064.
nvd
CVE-2015-6267P3HIGHCVSS 7.8v2.2.1v2.2.22015-08-29
CVE-2015-6267 [HIGH] CWE-399 CVE-2015-6267: Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted L2TP packet, aka Bug IDs CSCsw95722 and CSCsw95496.
nvd
CVE-2013-5547P3HIGHCVSS 7.8v3.9.0sv3.9.1s2013-10-31
CVE-2013-5547 [HIGH] CWE-20 CVE-2013-5547: Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of serv
Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) by sending malformed EoGRE packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCuf08269.
nvd
CVE-2013-5546P3HIGHCVSS 7.8v3.7.0sv3.7.1s+2 more2013-10-31
CVE-2013-5546 [HIGH] CWE-20 CVE-2013-5546: The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devic
The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via large TCP packets that are processed by the (1) NAT or (2) ALG component, aka Bug ID CSCud72509.
nvd
CVE-2010-2835P3HIGHCVSS 7.8v2.5.0v2.5.1+2 more2010-09-23
CVE-2010-2835 [HIGH] CVE-2010-2835: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7.0(2a)su3, 7.1su before 7.1(3b)su2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allow remote attackers to cause a denial of service (device reload or voice-services ou
nvd
CVE-2011-0945P3HIGHCVSS 7.8v3.1.0sv3.1.1s+2 more2011-10-03
CVE-2011-0945 [HIGH] CWE-399 CVE-2011-0945: Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 th
Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xS before 3.1.3S and 3.2.xS before 3.2.1S, when implemented over Fast Sequence Transport (FST), allows remote attackers to cause a denial of service (memory consumption and device reload or hang) via a crafted IP protocol 91 pac
nvd