cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 17 of 26
CVE-2014-2146P3MEDIUMCVSS 6.5≤ 15.4\(3\)s2016-09-22
CVE-2014-2146 [MEDIUM] CWE-20 CVE-2014-2146: The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, po The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoofed traffic that matches one of these sessions, aka Bug IDs CSCun94946 and CSCun96847.
nvd
CVE-2021-34703P3MEDIUMCVSS 6.5≤ 16.12.32021-09-23
CVE-2021-34703 [MEDIUM] CWE-456 CVE-2021-34703: A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper initialization of a buffer. An attacker could exploit this vulnerability
nvd
CVE-2021-1383P3MEDIUMCVSS 6.7v16.9.1v16.9.2+60 more2021-03-24
CVE-2021-1383 [MEDIUM] CWE-20 CVE-2021-1383: Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, lo Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI commands. An attacker could exploit these vulnerabilities by authenticating to the device and submi
nvd
CVE-2019-12661P3MEDIUMCVSS 6.7v15.3\(3\)sv15.4\(2\)s+5 more2019-09-25
CVE-2019-12661 [MEDIUM] CWE-77 CVE-2019-12661: A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software coul A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific VMAN CLI command on th
nvd
CVE-2021-34729P3MEDIUMCVSS 6.7≤ 17.3.1a2021-09-23
CVE-2021-34729 [MEDIUM] CWE-77 CVE-2021-34729: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to insufficient validation of arguments passed to certain CLI commands. An attacker could exploit this vulnerability by
nvd
CVE-2022-20855P3MEDIUMCVSS 6.7v17.6.12022-09-30
CVE-2022-20855 [MEDIUM] CWE-266 CVE-2022-20855: A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Con A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst Access Points could allow an authenticated, local attacker to escape the restricted controller shell and execute arbitrary commands on the underlying operating system of the access point. This vulnerability is due to improper chec
nvd
CVE-2022-20676P3MEDIUMCVSS 6.7v16.12.1z2v17.2.1+27 more2022-04-15
CVE-2022-20676 [MEDIUM] CWE-250 CVE-2022-20676: A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root-level privileges. This vulnerability is due to insufficient input validation of data that is passed into the Tcl interpreter. An attacker could exploit this vulnerability by l
nvd
CVE-2021-34723P3MEDIUMCVSS 6.7v17.3.1a2021-09-23
CVE-2021-34723 [MEDIUM] CWE-668 CVE-2021-34723: A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an A vulnerability in a specific CLI command that is run on Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the configuration database of an affected device. This vulnerability is due to insufficient validation of specific CLI command parameters. An attacker could exploit this vulnerability by i
nvd
CVE-2021-1376P3MEDIUMCVSS 6.7v16.5.1v16.5.1a+48 more2021-03-24
CVE-2021-1376 [MEDIUM] CWE-347 CVE-2021-1376: Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Cataly Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating system, install and boot a malicious software image, or execute unsigned bin
nvd
CVE-2021-1375P3MEDIUMCVSS 6.7v16.5.1v16.5.1a+35 more2021-03-24
CVE-2021-1375 [MEDIUM] CWE-347 CVE-2021-1375: Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Cataly Multiple vulnerabilities in the fast reload feature of Cisco IOS XE Software running on Cisco Catalyst 3850, Cisco Catalyst 9300, and Cisco Catalyst 9300L Series Switches could allow an authenticated, local attacker to either execute arbitrary code on the underlying operating system, install and boot a malicious software image, or execute unsigned bin
nvd
CVE-2024-20414P3MEDIUMCVSS 6.5v3.2.0sev3.2.0sg+429 more2024-09-25
CVE-2024-20414 [MEDIUM] CWE-285 CVE-2024-20414: A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI. This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could e
nvd
CVE-2018-0131P3MEDIUMCVSS 5.9v15.5\(3\)s2018-08-14
CVE-2018-0131 [MEDIUM] CWE-326 CVE-2018-0131: A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypted nonces of an Internet Key Exchange Version 1 (IKEv1) session. The vulnerability exists because the affected software responds incorrectly to decryption failures. An attack
nvd
CVE-2014-3357P4HIGHCVSS 7.8v3.3\(.0\)xov3.3.0se+4 more2014-09-25
CVE-2014-3357 [HIGH] CWE-78 CVE-2014-3357: Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5. Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allow remote attackers to cause a denial of service (device reload) via malformed mDNS packets, aka Bug ID CSCul90866.
nvd
CVE-2011-3272P4HIGHCVSS 7.8v2.1.0v2.1.1+27 more2011-10-03
CVE-2011-3272 [HIGH] CWE-399 CVE-2011-3272: The IP Service Level Agreement (IP SLA) functionality in Cisco IOS 15.1, and IOS XE 2.1.x through 3. The IP Service Level Agreement (IP SLA) functionality in Cisco IOS 15.1, and IOS XE 2.1.x through 3.3.x, allows remote attackers to cause a denial of service (memory corruption and device reload) via malformed IP SLA packets, aka Bug ID CSCtk67073.
nvd
CVE-2014-2106P4HIGHCVSS 7.8v3.10.0sv3.10.1s12014-03-27
CVE-2014-2106 [HIGH] CWE-20 CVE-2014-2106: Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898.
nvd
CVE-2012-1311P3HIGHCVSS 7.8v3.2.0sv3.2.1s+3 more2012-03-29
CVE-2012-1311 [HIGH] CWE-399 CVE-2012-1311: The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a V The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID CSCts80643.
nvd
CVE-2015-6271P4HIGHCVSS 7.8v2.1.0v2.1.1+14 more2015-08-31
CVE-2015-6271 [HIGH] CWE-399 CVE-2015-6271: Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway i Cisco IOS XE 2.1.0 through 2.4.3 and 2.5.0 on ASR 1000 devices, when NAT Application Layer Gateway is used, allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted SIP packet, aka Bug IDs CSCta74749 and CSCta77008.
nvd
CVE-2014-2113P4HIGHCVSS 7.8v3.3.0sv3.3.0sg+28 more2014-03-27
CVE-2014-2113 [HIGH] CWE-20 CVE-2014-2113: Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, a Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.
nvd
CVE-2013-2779P4HIGHCVSS 7.8v3.4.0asv3.4.0s+13 more2013-04-11
CVE-2013-2779 [HIGH] CVE-2013-2779: Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Servic Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vu
nvd
CVE-2013-5473P4HIGHCVSS 7.8v3.4.2sv3.4.3s+3 more2013-09-27
CVE-2013-5473 [HIGH] CWE-399 CVE-2013-5473: Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS befor Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS before 3.6.1S allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed IKEv1 packets, aka Bug ID CSCtx66011.
nvd