cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 20 of 26
CVE-2017-6615P4MEDIUMCVSS 6.3v3.16.0csv3.16.0s+3 more2017-04-20
CVE-2017-6615 [MEDIUM] CWE-399 CVE-2017-6615: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 coul A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when the affected software processes an SNMP read request that contains certain criteria for a specific
nvd
CVE-2020-3207P4MEDIUMCVSS 6.7v16.9.2v16.9.2a+17 more2020-06-03
CVE-2020-3207 [MEDIUM] CWE-77 CVE-2020-3207: A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could a A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. This vulnerability is due to insufficient input validation checks while processing boot options
nvd
CVE-2022-20692P4MEDIUMCVSS 6.5v3.15.1xbsv3.15.2xbs+125 more2022-04-15
CVE-2022-20692 [MEDIUM] CWE-400 CVE-2022-20692: A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privilege A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to insufficient resource management. An attacker could exploit this vulnerability by initiating a large number of NETCONF o
nvd
CVE-2020-3213P4MEDIUMCVSS 6.7v3.8.0sv3.8.1s+190 more2020-06-03
CVE-2020-3213 [MEDIUM] CWE-264 CVE-2020-3213: A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user of the underlying operating system. The vulnerability is due to the ROMMON allowing for special parameters to be passed to the device at initial boot up. An attacker could exploit this vulnerability by send
nvd
CVE-2019-1742P4MEDIUMCVSS 5.3v3.2.0jav16.3.1+21 more2019-03-28
CVE-2019-1742 [MEDIUM] CWE-16 CVE-2019-1742: A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attack A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information. The vulnerability is due to improper access control to files within the web UI. An attacker could exploit this vulnerability by sending a malicious request to an affected device. A successful exploit coul
nvd
CVE-2011-3275P4HIGHCVSS 7.8v2.5.0v2.5.1+12 more2011-10-03
CVE-2011-3275 [HIGH] CWE-399 CVE-2011-3275: Memory leak in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attacke Memory leak in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted SIP message, aka Bug ID CSCti48504.
nvd
CVE-2021-1224P4MEDIUMCVSS 5.3fixed in 17.4.12021-01-13
CVE-2021-1224 [MEDIUM] CWE-693 CVE-2021-1224: Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjun Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the
nvd
CVE-2021-34705P4MEDIUMCVSS 5.3v3.7.0bsv3.7.0s+279 more2021-09-23
CVE-2021-34705 [MEDIUM] CWE-232 CVE-2021-34705: A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cis A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces.
nvd
CVE-2015-0681P4HIGHCVSS 7.1v2.5.0v2.5.1+51 more2015-07-24
CVE-2015-0681 [HIGH] CWE-399 CVE-2015-0681: The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15 The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15.0(2)ED1, 15.0(2)EY3, 15.1(3)SVF4a, and 15.2(2)JB1 and IOS XE 2.5.x, 2.6.x, 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, and 3.5.xS before 3.6.0S; 3.1.xSG, 3.2.xSG, and 3.3.xSG before 3.4.0SG; 3.2.xSE before 3.3.0SE; 3.2.xXO before 3.3.0XO; 3.2.xSQ; 3.3.xSQ; and 3.4.x
nvd
CVE-2025-20194P4MEDIUMCVSS 5.4v17.3.1v17.3.1a+96 more2025-05-07
CVE-2025-20194 [MEDIUM] CWE-78 CVE-2025-20194: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authen A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based mana
nvd
CVE-2021-1398P4MEDIUMCVSS 6.8v3.7.0bsv3.7.0s+255 more2021-03-24
CVE-2021-1398 [MEDIUM] CWE-489 CVE-2021-1398: A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attac A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operating system of an affected device. This vulnerability is due to incorrect validations of specific function arguments
nvd
CVE-2019-1649P4MEDIUMCVSS 6.7fixed in 16.12.1fixed in 16.3.9+7 more2019-05-13
CVE-2019-1649 [MEDIUM] CWE-284 CVE-2019-1649: A vulnerability in the logic that handles access control to one of the hardware components in Cisco' A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vuln
nvd
CVE-2017-3850P4MEDIUMCVSS 5.9v3.7.0ev3.7.1e+79 more2017-03-21
CVE-2017-3850 [MEDIUM] CWE-20 CVE-2017-3850: A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4 A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4 through 15.6) and Cisco IOS XE Software (3.7 through 3.18, and 16) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certain crafted packets. An attac
nvd
CVE-2018-15371P4MEDIUMCVSS 6.7v16.3\(1\)2018-10-05
CVE-2018-15371 [MEDIUM] CWE-284 CVE-2018-15371: A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authen A vulnerability in the shell access request mechanism of Cisco IOS XE Software could allow an authenticated, local attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists because the affected software has insufficient authentication mechanisms for certain commands. An attacker
nvd
CVE-2021-1441P4MEDIUMCVSS 6.7v3.15.1xbsv3.15.2xbs+25 more2021-03-24
CVE-2021-1441 [MEDIUM] CWE-78 CVE-2021-1441: A vulnerability in the hardware initialization routines of Cisco IOS XE Software for Cisco 1100 Seri A vulnerability in the hardware initialization routines of Cisco IOS XE Software for Cisco 1100 Series Industrial Integrated Services Routers and Cisco ESR6300 Embedded Series Routers could allow an authenticated, local attacker to execute unsigned code at system boot time. This vulnerability is due to incorrect validations of parameters passed to a di
nvd
CVE-2021-1281P4MEDIUMCVSS 6.7v16.9.1v16.9.2+57 more2021-03-24
CVE-2021-1281 [MEDIUM] CWE-399 CVE-2021-1281: A vulnerability in CLI management in Cisco IOS XE SD-WAN Software could allow an authenticated, loca A vulnerability in CLI management in Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system as the root user. This vulnerability is due to the way the software handles concurrent CLI sessions. An attacker could exploit this vulnerability by authenticating to the device as an administrative u
nvd
CVE-2017-6606P4MEDIUMCVSS 6.4v3.1.0sv3.1.0sg+162 more2017-04-07
CVE-2017-6606 [MEDIUM] CWE-78 CVE-2017-6606: A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More Information: CSCuz06639 CSCuz42122. Known Affected Releases: 15.6(1.1)S 16.1.2 16.2.0 15.2(1)E. Known
nvd
CVE-2016-6438P4MEDIUMCVSS 5.9v3.16.0csv3.16.0s+15 more2016-10-27
CVE-2016-6438 [MEDIUM] CWE-264 CVE-2016-6438: A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could al A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a configuration integrity change to the vty line configuration on an affected device. This vulnerability affects the following releases of Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband
nvd
CVE-2019-1757P4MEDIUMCVSS 5.9v3.6.4ev3.6.5ae+106 more2019-03-28
CVE-2019-1757 [MEDIUM] CWE-295 CVE-2019-1757: A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by
nvd
CVE-2017-12228P4MEDIUMCVSS 5.9≤ 15.4\(3\)sv3.3.0xo+143 more2017-09-29
CVE-2017-12228 [MEDIUM] CWE-20 CVE-2017-12228: A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Ci A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An atta
nvd