Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
28
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 14 of 26
CVE-2019-1649MEDIUMCVSS 6.7fixed in 16.12.1fixed in 16.3.9+7 more2019-05-13
CVE-2019-1649 [MEDIUM] CWE-284 CVE-2019-1649: A vulnerability in the logic that handles access control to one of the hardware components in Cisco' A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vuln
nvd
CVE-2019-1748HIGHCVSS 7.4v3.3.0sev3.3.0xo+179 more2019-03-28
CVE-2019-1748 [HIGH] CWE-295 CVE-2019-1748: A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS X A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplyi
nvd
CVE-2019-1741HIGHCVSS 7.5v3.2.0jav16.6.1+12 more2019-03-28
CVE-2019-1741 [HIGH] CWE-20 CVE-2019-1741: A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software coul A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been fre
nvd
CVE-2019-1750HIGHCVSS 7.4v3.6.0aev3.6.0be+40 more2019-03-28
CVE-2019-1750 [HIGH] CWE-20 CVE-2019-1750: A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload. The vulnerability is due to incomplete error handling when processing Cisco Discovery Protocol (CDP) packets used with the Easy Virtual Switching System. An
nvd
CVE-2019-1753HIGHCVSS 8.8v3.2.0jav3.6.10e+13 more2019-03-28
CVE-2019-1753 [HIGH] CWE-20 CVE-2019-1753: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services Management Agent (WSMA) functions. An attacker could exploit this vulnerability by su
nvd
CVE-2019-1752HIGHCVSS 7.5v3.8.0sv3.8.1s+127 more2019-03-28
CVE-2019-1752 [HIGH] CWE-20 CVE-2019-1752: A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of specific values in the Q.931 information elements. An attacker could exploit this vulnerability by calling the affected device with specifi
nvd
CVE-2019-1738HIGHCVSS 7.5v3.2.0jav3.16.0as+53 more2019-03-28
CVE-2019-1738 [HIGH] CWE-20 CVE-2019-1738: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit these vulnerabilities by sending crafted DNS packets throu
nvd
CVE-2019-1743HIGHCVSS 8.8v16.2.1v16.2.2+29 more2019-03-28
CVE-2019-1743 [HIGH] CWE-20 CVE-2019-1743: A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remot A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the device. An exploit co
nvd
CVE-2019-1747HIGHCVSS 8.6v16.10.12019-03-28
CVE-2019-1747 [HIGH] CWE-20 CVE-2019-1747: A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of C A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to improper processing of SMS protocol data units (PDUs) that are enc
nvd
CVE-2019-1739HIGHCVSS 7.5v3.2.0jav3.16.0as+53 more2019-03-28
CVE-2019-1739 [HIGH] CWE-20 CVE-2019-1739: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through
nvd
CVE-2019-1749HIGHCVSS 7.4v3.13.6asv3.16.0as+46 more2019-03-28
CVE-2019-1749 [HIGH] CWE-20 CVE-2019-1749: A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Ser A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the software insufficient
nvd
CVE-2019-1745HIGHCVSS 7.8v3.6.10ev3.10.0s+153 more2019-03-28
CVE-2019-1745 [HIGH] CWE-78 CVE-2019-1745: A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbi A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with elevated privileges. The vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input t
nvd
CVE-2019-1740HIGHCVSS 8.6v3.2.0jav3.16.0as+56 more2019-03-28
CVE-2019-1740 [HIGH] CWE-20 CVE-2019-1740: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability are due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through
nvd
CVE-2019-1754HIGHCVSS 8.8v3.2.0jav16.7.1+14 more2019-03-28
CVE-2019-1754 [HIGH] CWE-20 CVE-2019-1754: A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated A vulnerability in the authorization subsystem of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to improper validation of user privileges of web UI users. An attacker could exploit this vulnerability by submitting a maliciou
nvd
CVE-2019-1755HIGHCVSS 7.2v3.2.0jav3.6.10e+36 more2019-03-28
CVE-2019-1755 [HIGH] CWE-20 CVE-2019-1755: A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could A vulnerability in the Web Services Management Agent (WSMA) function of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary Cisco IOS commands as a privilege level 15 user. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker could exploit this vulnerability by su
nvd
CVE-2019-1756HIGHCVSS 7.2v3.2.0jav16.7.1+12 more2019-03-28
CVE-2019-1756 [HIGH] CWE-20 CVE-2019-1756: A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute co A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid administrator access to an affected device could exp
nvd
CVE-2019-1762MEDIUMCVSS 4.4v16.6.1v16.6.2+26 more2019-03-28
CVE-2019-1762 [MEDIUM] CWE-200 CVE-2019-1762: A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authen A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed at encryption time, when affected software handles configuration updates. An attacker could exploit th
nvd
CVE-2019-1759MEDIUMCVSS 5.3v3.2.0jav16.2.1+43 more2019-03-28
CVE-2019-1759 [MEDIUM] CWE-284 CVE-2019-1759: A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interf A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16
nvd
CVE-2019-1760MEDIUMCVSS 5.9v3.2.0jav3.16.4as+39 more2019-03-28
CVE-2019-1760 [MEDIUM] CWE-20 CVE-2019-1760: A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an una A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload. The vulnerability is due to the processing of malformed smart probe packets. An attacker could exploit this vulnerability by sending specially crafted smart probe packets at the affect
nvd
CVE-2019-1757MEDIUMCVSS 5.9v3.6.4ev3.6.5ae+106 more2019-03-28
CVE-2019-1757 [MEDIUM] CWE-295 CVE-2019-1757: A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by
nvd