cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 16 of 26
CVE-2013-1164P3HIGHCVSS 7.8v3.4.0asv3.4.0s+5 more2013-04-11
CVE-2013-1164 [HIGH] CVE-2013-1164: Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 multicast packets, aka Bug ID CSCtz97563.
nvd
CVE-2013-1165P3HIGHCVSS 7.8≤ 3.4.3sv2.1.0+29 more2013-04-11
CVE-2013-1165 [HIGH] CWE-20 CVE-2013-1165: Cisco IOS XE 2.x and 3.x before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregatio Cisco IOS XE 2.x and 3.x before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) allows remote attackers to cause a denial of service (card reload) by sending many crafted L2TP packets, aka Bug ID CSCtz23293.
nvd
CVE-2013-5475P3HIGHCVSS 7.8v2.1.0v2.1.1+59 more2013-09-27
CVE-2013-5475 [HIGH] CWE-20 CVE-2013-5475: Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attacke Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.
nvd
CVE-2010-2834P3HIGHCVSS 7.8v2.5.0v2.5.1+2 more2010-09-23
CVE-2010-2834 [HIGH] CVE-2010-2834: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)SU1, 7.x before 7.1(5), and 8.0 before 8.0(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via crafted SIP registration traffic ov
nvd
CVE-2010-2829P3HIGHCVSS 7.8v2.5.0v2.5.1+1 more2010-09-23
CVE-2010-2829 [HIGH] CVE-2010-2829: Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 throug Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 2.5.x before 2.5.2 and 2.6.x before 2.6.1, allows remote attackers to cause a denial of service (traceback and device reload) via crafted H.323 packets, aka Bug ID CSCtd33567.
nvd
CVE-2010-2831P3HIGHCVSS 7.8v2.5.0v2.5.1+2 more2010-09-23
CVE-2010-2831 [HIGH] CVE-2010-2831: Unspecified vulnerability in the NAT for SIP implementation in Cisco IOS 12.1 through 12.4 and 15.0 Unspecified vulnerability in the NAT for SIP implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1 allows remote attackers to cause a denial of service (device reload) via transit traffic on UDP port 5060, aka Bug ID CSCtf17624.
nvd
CVE-2010-2833P3HIGHCVSS 7.8v2.5.0v2.5.1+2 more2010-09-23
CVE-2010-2833 [HIGH] CVE-2010-2833: Unspecified vulnerability in the NAT for H.225.0 implementation in Cisco IOS 12.1 through 12.4 and 1 Unspecified vulnerability in the NAT for H.225.0 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1 allows remote attackers to cause a denial of service (device reload) via transit traffic, aka Bug ID CSCtd86472.
nvd
CVE-2010-2832P3HIGHCVSS 7.8v2.5.0v2.5.1+2 more2010-09-23
CVE-2010-2832 [HIGH] CVE-2010-2832: Unspecified vulnerability in the NAT for H.323 implementation in Cisco IOS 12.1 through 12.4 and 15. Unspecified vulnerability in the NAT for H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1 allows remote attackers to cause a denial of service (device reload) via transit traffic, aka Bug ID CSCtf91428.
nvd
CVE-2010-2828P3HIGHCVSS 7.8v2.5.0v2.5.1+1 more2010-09-23
CVE-2010-2828 [HIGH] CVE-2010-2828: Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 throug Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 2.5.x before 2.5.2 and 2.6.x before 2.6.1, allows remote attackers to cause a denial of service (device reload) via crafted H.323 packets, aka Bug ID CSCtc73759.
nvd
CVE-2011-3280P3HIGHCVSS 7.5v3.1.0sgv3.1.1sg2011-10-03
CVE-2011-3280 [HIGH] CWE-399 CVE-2011-3280: Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCtj04672.
nvd
CVE-2017-3849P3HIGHCVSS 7.4v3.7.0ev3.7.1e+82 more2017-03-21
CVE-2017-3849 [HIGH] CWE-20 CVE-2017-3849: A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Soft A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS XE Software (possibly 3.7 through 3.18, and 16) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certa
nvd
CVE-2018-15373P3HIGHCVSS 7.4v15.5\(3\)s3.162018-10-05
CVE-2018-15373 [HIGH] CWE-399 CVE-2018-15373: A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Softwar A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory handling by the affected software when t
nvd
CVE-2020-3409P3HIGHCVSS 7.4v15.2\(7\)ev16.11.1a2020-09-24
CVE-2020-3409 [HIGH] CWE-20 CVE-2020-3409: A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to crash and reload, resulting in a denial of service (DoS) condition on the device. The vulnerability is due to insufficient processing logic for crafted PROFINET packets that are sent to an
nvd
CVE-2020-3497P3HIGHCVSS 7.4v16.12.12020-09-24
CVE-2020-3497 [HIGH] CWE-20 CVE-2020-3497: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient val
nvd
CVE-2020-3493P3HIGHCVSS 7.4v16.12.12020-09-24
CVE-2020-3493 [HIGH] CWE-20 CVE-2020-3493: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient val
nvd
CVE-2020-3489P3HIGHCVSS 7.4v16.12.12020-09-24
CVE-2020-3489 [HIGH] CWE-20 CVE-2020-3489: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient val
nvd
CVE-2020-3488P3HIGHCVSS 7.4v16.12.12020-09-24
CVE-2020-3488 [HIGH] CWE-20 CVE-2020-3488: Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition of an affected device. These vulnerabilities are due to insufficient val
nvd
CVE-2024-20354P3HIGHCVSS 7.4≥ 16.12.4a, < 17.1.0≥ 17.3.0, < 17.3.9+3 more2024-03-27
CVE-2024-20354 [HIGH] CWE-460 CVE-2024-20354: A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Soft A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed frames. An attacker could exploit th
nvd
CVE-2024-20313P3HIGHCVSS 7.4v17.5.1v17.5.1a+36 more2024-04-24
CVE-2024-20313 [HIGH] CWE-120 CVE-2024-20313: A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unaut A vulnerability in the OSPF version 2 (OSPFv2) feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of OSPF updates that are processed by a device. An attacker could exploi
nvd
CVE-2019-1759P3MEDIUMCVSS 5.3v3.2.0jav16.2.1+43 more2019-03-28
CVE-2019-1759 [MEDIUM] CWE-284 CVE-2019-1759: A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interf A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability is due to a logic error that was introduced in the Cisco IOS XE Software 16
nvd