cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 19 of 26
CVE-2018-0183P4MEDIUMCVSS 6.7fixed in 3.13.2asfixed in 3.13.5as+9 more2018-03-28
CVE-2018-0183 [MEDIUM] CWE-264 CVE-2018-0183: A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attac A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability is due to the affected software improperly sanitizing command arguments to prevent access to inte
nvd
CVE-2018-15368P4MEDIUMCVSS 6.7v15.4\(3\)s2018-10-05
CVE-2018-15368 [MEDIUM] CWE-20 CVE-2018-15368: A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attac A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerability is due to the affected software improperly sanitizing command arguments to prevent modifications
nvd
CVE-2020-3204P4MEDIUMCVSS 6.7v3.2.0sev3.2.0sg+323 more2020-06-03
CVE-2020-3204 [MEDIUM] CWE-20 CVE-2020-3204: A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS X A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to t
nvd
CVE-2021-1390P4MEDIUMCVSS 6.7v16.8.1v16.8.1a+72 more2021-03-24
CVE-2021-1390 [MEDIUM] CWE-123 CVE-2021-1390: A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an a A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker would need to have valid user credentials at privilege level 15. This vulnerability exists because the affected software permits mo
nvd
CVE-2020-3513P4MEDIUMCVSS 6.7v16.12.1v17.22020-09-24
CVE-2020-3513 [MEDIUM] CWE-749 CVE-2020-3513: Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenticated, local attacker with high privileges to execute persistent code at bootup and break the chain of trust. Thes
nvd
CVE-2020-3416P4MEDIUMCVSS 6.7v16.12.1v17.22020-09-24
CVE-2020-3416 [MEDIUM] CWE-749 CVE-2020-3416: Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenticated, local attacker with high privileges to execute persistent code at bootup and break the chain of trust. Thes
nvd
CVE-2023-20097P4MEDIUMCVSS 6.7fixed in 16.12.8≥ 17.1, < 17.3.6+2 more2023-03-23
CVE-2023-20097 [MEDIUM] CWE-77 CVE-2023-20097: A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator access to the CLI of the controller
nvd
CVE-2025-20201P4MEDIUMCVSS 6.7v3.2.0sev3.2.1se+408 more2025-05-07
CVE-2025-20201 [MEDIUM] CWE-754 CVE-2025-20201: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker wit A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with privilege level 15 to elevate privileges to root on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation when processing specific configuration commands. An attacker could exploit this vul
nvd
CVE-2021-34696P4MEDIUMCVSS 5.8≤ 17.3.22021-09-23
CVE-2021-34696 [MEDIUM] CWE-284 CVE-2021-34696: A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Agg A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is configured using a method other than the configuration CLI. An attacker
nvd
CVE-2021-1236P4MEDIUMCVSS 5.3fixed in 17.4.12021-01-13
CVE-2021-1236 [MEDIUM] CWE-670 CVE-2021-1236: Multiple Cisco products are affected by a vulnerability in the Snort application detection engine th Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would
nvd
CVE-2013-5543P4HIGHCVSS 7.8v3.4.0asv3.4.0s+1 more2013-10-31
CVE-2013-5543 [HIGH] CWE-20 CVE-2013-5543: Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to Cisco IOS XE 3.4 before 3.4.2S and 3.5 before 3.5.1S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) via malformed ICMP error packets associated with a (1) TCP or (2) UDP session that is under inspection by the Zone-Based Firewall (ZBFW) component, aka Bug ID CSCtt26470.
nvd
CVE-2011-0946P4HIGHCVSS 7.8v3.1.0sgv3.1.1sg2011-10-03
CVE-2011-0946 [HIGH] CVE-2011-0946: The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, all The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic, aka Bug ID CSCtd10712.
nvd
CVE-2025-20155P3MEDIUMCVSS 6.0v17.9.4v17.9.4a+26 more2025-05-07
CVE-2025-20155 [MEDIUM] CWE-1287 CVE-2025-20155: A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, loca A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software when a device is first deployed in SD-WAN mode or when an administrator co
nvd
CVE-2021-1495P4MEDIUMCVSS 5.3≥ 16.12, < 16.12.5≥ 17.1, < 17.3.3+1 more2021-04-29
CVE-2021-1495 [MEDIUM] CWE-755 CVE-2021-1495: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through a
nvd
CVE-2018-0471P4HIGHCVSS 7.4v16.6.1v16.6.22018-10-05
CVE-2018-0471 [HIGH] CWE-400 CVE-2018-0471: A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6. A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memory leak that may lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain CDP packets. An attacker could exploit this vulnerabili
nvd
CVE-2019-1750P4HIGHCVSS 7.4v3.6.0aev3.6.0be+40 more2019-03-28
CVE-2019-1750 [HIGH] CWE-20 CVE-2019-1750: A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload. The vulnerability is due to incomplete error handling when processing Cisco Discovery Protocol (CDP) packets used with the Easy Virtual Switching System. An
nvd
CVE-2019-1749P4HIGHCVSS 7.4v3.13.6asv3.16.0as+46 more2019-03-28
CVE-2019-1749 [HIGH] CWE-20 CVE-2019-1749: A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Ser A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability exists because the software insufficient
nvd
CVE-2020-3511P4HIGHCVSS 7.4v15.1\(4\)m2020-09-24
CVE-2020-3511 [HIGH] CWE-20 CVE-2020-3511: A vulnerability in the ISDN subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the ISDN subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the ISDN Q.931 messages are processed. An attacker could exploit t
nvd
CVE-2020-3512P4HIGHCVSS 7.4v15.2\(7\)e2020-09-24
CVE-2020-3512 [HIGH] CWE-388 CVE-2020-3512: A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco I A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a crash on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of LLDP messages in the P
nvd
CVE-2020-3396P4HIGHCVSS 7.2v16.12.12020-09-24
CVE-2020-3396 [HIGH] CWE-284 CVE-2020-3396: A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections. The vulnerability occurs because the USB 3.0 SSD control data is not stored o
nvd
Cisco IOS XE vulnerabilities | cvebase