cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 15 of 26
CVE-2011-3277P3HIGHCVSS 7.8v3.1.0sgv3.1.1sg2011-10-03
CVE-2011-3277 [HIGH] CVE-2011-3277: Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted H.323 packets to TCP port 1720, aka Bug ID CSCth11006.
nvd
CVE-2011-3278P3HIGHCVSS 7.8v3.1.0sgv3.1.1sg2011-10-03
CVE-2011-3278 [HIGH] CVE-2011-3278: Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCti48483.
nvd
CVE-2011-3276P3HIGHCVSS 7.8v3.1.0sgv3.1.1sg2011-10-03
CVE-2011-3276 [HIGH] CVE-2011-3276: Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) by sending crafted SIP packets to TCP port 5060, aka Bug ID CSCso02147.
nvd
CVE-2015-6268P3HIGHCVSS 7.8v2.2.1v2.2.22015-08-29
CVE-2015-6268 [HIGH] CWE-399 CVE-2015-6268: Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service ( Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted IPv4 UDP packet, aka Bug ID CSCsw95482.
nvd
CVE-2016-1349P3HIGHCVSS 7.5v3.2ja_3.2.0jav3.2se_3.2.0se+30 more2016-03-26
CVE-2016-1349 [HIGH] CWE-399 CVE-2016-1349: The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.
nvd
CVE-2016-1348P3HIGHCVSS 7.5v3.3xo_3.3.0xov3.3xo_3.3.1xo+75 more2016-03-26
CVE-2016-1348 [HIGH] CWE-399 CVE-2016-1348: Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.
nvd
CVE-2018-0469P3MEDIUMCVSS 6.8v16.5.12018-10-05
CVE-2018-0469 [MEDIUM] CWE-415 CVE-2018-0469: A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, r A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a double-free-in-memory handling by the affected software when specific HTTP requests are processed. An attacker could exploit this vulnerability by sending specific HTTP
nvd
CVE-2020-3390P3HIGHCVSS 7.4v16.12.12020-09-24
CVE-2020-3390 [HIGH] CWE-20 CVE-2020-3390: A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause the device to unexpectedly reload, causing a denial of service (DoS) condition on an affected device. The vulnerabi
nvd
CVE-2021-1403P3HIGHCVSS 7.4v3.15.1xbsv3.15.2xbs+121 more2021-03-24
CVE-2021-1403 [HIGH] CWE-345 CVE-2021-1403: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remot A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient HTTP protections in the web UI on an affected device. An attacker could ex
nvd
CVE-2024-20303P3HIGHCVSS 7.4v17.2.1v17.2.1a+66 more2024-03-27
CVE-2024-20303 [HIGH] CWE-459 CVE-2024-20303: A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LA A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper management of mDNS client entries. An attacker could exploit this vulnerability by connecting to t
nvd
CVE-2025-20140P3HIGHCVSS 7.4v16.4.1v16.4.2+192 more2025-05-07
CVE-2025-20140 [HIGH] CWE-789 CVE-2025-20140: A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent wireless attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of I
nvd
CVE-2021-1382P3MEDIUMCVSS 6.7fixed in 17.3.3≥ 17.4.1, ≤ 17.4.2+2 more2021-03-24
CVE-2021-1382 [MEDIUM] CWE-77 CVE-2021-1382: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root privileges on the underlying operating system. This vulnerability is due to insufficient input validation on certain CLI commands. An attacker could exploit this vulnerability by authenticating to
nvd
CVE-2024-20306P3MEDIUMCVSS 6.7v17.10.1v17.10.1a+7 more2024-03-27
CVE-2024-20306 [MEDIUM] CWE-233 CVE-2024-20306: A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level 15 privileges on the affected device. This vulnerability is due to insuff
nvd
CVE-2014-3358P3HIGHCVSS 7.8v3.3\(.0\)xov3.3.0se+4 more2014-09-25
CVE-2014-3358 [HIGH] CWE-78 CVE-2014-3358: Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO befor Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allows remote attackers to cause a denial of service (memory consumption, and interface queue wedge or device reload) via malformed mDNS packets, aka Bug ID CSCuj58950.
nvd
CVE-2014-3359P3HIGHCVSS 7.8v3.4.0sv3.4.1s+28 more2014-09-25
CVE-2014-3359 [HIGH] CWE-399 CVE-2014-3359: Memory leak in Cisco IOS 15.1 through 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7. Memory leak in Cisco IOS 15.1 through 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; and 3.11.xS before 3.12S allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed DHCPv6 packets, aka Bug ID CSCum90081.
nvd
CVE-2011-3279P3HIGHCVSS 7.8v3.1.0sgv3.1.1sg2011-10-03
CVE-2011-3279 [HIGH] CVE-2011-3279: The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.
nvd
CVE-2014-2108P3HIGHCVSS 7.8v3.2.0sv3.2.0sg+59 more2014-03-27
CVE-2014-2108 [HIGH] CWE-20 CVE-2014-2108: Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 b Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a denial of service (device reload) via a malformed IKEv2 packet, aka Bug ID CSCui88426.
nvd
CVE-2015-6282P3HIGHCVSS 7.8v2.1.0v2.1.1+93 more2015-09-26
CVE-2015-6282 [HIGH] CWE-20 CVE-2015-6282: Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers to cause a denial of service (device reload) via IPv4 packets that require NAT and MPLS actions, aka Bug ID CSCut96933.
nvd
CVE-2013-1148P3HIGHCVSS 7.8v3.1.0sv3.1.1s+17 more2013-03-28
CVE-2013-1148 [HIGH] CWE-119 CVE-2013-1148: The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15 The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S allows remote attackers to cause a denial of service (device reload) via crafted (1) IPv4 or (2) IPv6 IP SLA packets on UDP port 1167, aka Bug ID CSCuc72594.
nvd
CVE-2015-0637P3HIGHCVSS 7.8v3.10s.0v3.10s.1+11 more2015-03-26
CVE-2015-0637 [HIGH] CWE-20 CVE-2015-0637: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15 The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka Bug ID CSCup62315.
nvd