cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 21 of 26
CVE-2021-1625P4MEDIUMCVSS 5.8fixed in 17.3.22021-09-23
CVE-2021-1625 [MEDIUM] CWE-284 CVE-2021-1625: A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an un A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP responder-to-initiator flows are not inspected when the Zone-Based Policy Firewall has either Uni
nvd
CVE-2020-3223P4MEDIUMCVSS 4.9v16.9.4v16.9.4c+13 more2020-06-03
CVE-2020-3223 [MEDIUM] CWE-59 CVE-2020-3223: A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an aut A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to read arbitrary files on the underlying filesystem of the device. The vulnerability is due to insufficient file scope limiting. An attacker could exploit this vulnerability by creating a specif
nvd
CVE-2013-5472P4HIGHCVSS 7.1v2.1.0v2.1.1+38 more2013-09-27
CVE-2013-5472 [HIGH] CWE-20 CVE-2013-5472: The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.
nvd
CVE-2021-1453P4MEDIUMCVSS 6.8v3.15.1xbsv3.15.2xbs+53 more2021-03-24
CVE-2021-1453 [MEDIUM] CWE-347 CVE-2021-1453: A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Ci A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. The vulnerability is due to an improper check in the code function that manages the verification of the digital signatur
nvd
CVE-2020-3417P4MEDIUMCVSS 6.7v3.18.0spv3.18.1asp+96 more2020-09-24
CVE-2020-3417 [MEDIUM] CWE-78 CVE-2020-3417: A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute per A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust. This vulnerability is due to incorrect validations by boot scripts when specific ROM monitor (ROMMON) variables are set. An attacker could exploit this vulnerability by installing code to a specific
nvd
CVE-2021-1391P4MEDIUMCVSS 6.7v3.9.0ev3.9.1e+88 more2021-03-24
CVE-2021-1391 [MEDIUM] CWE-489 CVE-2021-1391: A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, loc A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consen
nvd
CVE-2019-12649P4MEDIUMCVSS 6.7v16.8\(1\)2019-09-25
CVE-2019-12649 [MEDIUM] CWE-347 CVE-2019-12649: A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authentica A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability exists because, under certain circumstances, an affected device can be configured to not verify the digital signat
nvd
CVE-2019-1760P4MEDIUMCVSS 5.9v3.2.0jav3.16.4as+39 more2019-03-28
CVE-2019-1760 [MEDIUM] CWE-20 CVE-2019-1760: A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an una A vulnerability in Performance Routing Version 3 (PfRv3) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload. The vulnerability is due to the processing of malformed smart probe packets. An attacker could exploit this vulnerability by sending specially crafted smart probe packets at the affect
nvd
CVE-2021-1377P4MEDIUMCVSS 5.8v3.6.6ev3.6.7ae+166 more2021-03-24
CVE-2021-1377 [MEDIUM] CWE-399 CVE-2021-1377: A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent an affected device from resolving ARP entries for legitimate hosts on the connected subnets. This vulnerability exists because ARP entries are mismanaged. An attacker could exploit th
nvd
CVE-2021-1434P4MEDIUMCVSS 6.0v16.11.1v16.11.1a+25 more2021-03-24
CVE-2021-1434 [MEDIUM] CWE-552 CVE-2021-1434: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could exploit this vulnerability by issuing that command with specific paramete
nvd
CVE-2023-20246P4MEDIUMCVSS 5.3≥ 17.12, < 17.12.22023-11-01
CVE-2023-20246 [MEDIUM] CWE-290 CVE-2023-20246: Multiple Cisco products are affected by a vulnerability in Snort access control policies that could Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs when the access control policies are being populated. An attacker could exploit this vulnerability
nvd
CVE-2024-20316P4MEDIUMCVSS 5.3v16.3.1v16.3.1a+158 more2024-03-27
CVE-2024-20316 [MEDIUM] CWE-390 CVE-2024-20316: A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an u A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access resources that should have been protected by a configured IPv4 access control list (ACL). This vulnerability is due to improper handling of error conditions when a successfully authorized device administrator
nvd
CVE-2015-0688P4HIGHCVSS 7.1v13.10.2s2015-04-04
CVE-2015-0688 [HIGH] CWE-399 CVE-2015-0688: Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NA Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows remote attackers to cause a denial of service (module crash) via malformed H.323 packets, aka Bug ID CSCup21070.
nvd
CVE-2016-1428P4MEDIUMCVSS 6.5v3.15.0sv3.16.0s+1 more2016-06-23
CVE-2016-1428 [MEDIUM] CWE-399 CVE-2016-1428: Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug ID CSCux13174.
nvd
CVE-2023-20082P4MEDIUMCVSS 6.8fixed in 17.3.7≥ 17.4, < 17.6.5+1 more2023-03-23
CVE-2023-20082 [MEDIUM] CWE-78 CVE-2023-20082: A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an auth A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to errors that occur when retrieving th
nvd
CVE-2020-3209P4MEDIUMCVSS 6.8v3.2.0sev3.2.0sg+312 more2020-06-03
CVE-2020-3209 [MEDIUM] CWE-347 CVE-2020-3209: A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticat A vulnerability in software image verification in Cisco IOS XE Software could allow an unauthenticated, physical attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability is due to an improper check on the area of code that manages the verification of the digital signatures of system
nvd
CVE-2020-3215P4MEDIUMCVSS 6.7v3.7.0ev3.7.1e+222 more2020-06-03
CVE-2020-3215 [MEDIUM] CWE-264 CVE-2020-3215: A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authentica A vulnerability in the Virtual Services Container of Cisco IOS XE Software could allow an authenticated, local attacker to gain root-level privileges on an affected device. The vulnerability is due to insufficient validation of a user-supplied open virtual appliance (OVA). An attacker could exploit this vulnerability by installing a malicious OVA on a
nvd
CVE-2023-20081P4MEDIUMCVSS 5.9v17.8.12023-03-23
CVE-2023-20081 [MEDIUM] CWE-122 CVE-2023-20081: A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) S A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu
nvd
CVE-2017-12211P4MEDIUMCVSS 5.3v3.16.12017-09-07
CVE-2017-12211 [MEDIUM] CWE-399 CVE-2017-12211: A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IO A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device. The vulnerability is due to IPv6 sub block corruption. An attacker could exploit this vulnerability by polling the affected device IPv6 info
nvd
CVE-2009-1168P4HIGHCVSS 7.1v2.3v2.3.1t+2 more2009-07-30
CVE-2009-1168 [HIGH] CWE-399 CVE-2009-1168: Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12. Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (memory corrup
nvd