cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 22 of 26
CVE-2013-1167P4HIGHCVSS 7.1v3.2.00.xo.15.0\(2\)xov3.2.0s+21 more2013-04-11
CVE-2013-1167 [HIGH] CWE-22 CVE-2013-1167: Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (AS Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled during the processing of encapsulation, aka Bug ID CSCtt11558.
nvd
CVE-2025-20196P4MEDIUMCVSS 5.3v16.1.1v16.1.2+136 more2025-05-07
CVE-2025-20196 [MEDIUM] CWE-307 CVE-2025-20196: A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of HTTP reques
nvd
CVE-2010-2830P4HIGHCVSS 7.1v2.5.0v2.5.12010-09-23
CVE-2010-2830 [HIGH] CVE-2010-2830: The IGMPv3 implementation in Cisco IOS 12.2, 12.3, 12.4, and 15.0 and IOS XE 2.5.x before 2.5.2, whe The IGMPv3 implementation in Cisco IOS 12.2, 12.3, 12.4, and 15.0 and IOS XE 2.5.x before 2.5.2, when PIM is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed IGMP packet, aka Bug ID CSCte14603.
nvd
CVE-2015-6383P4HIGHCVSS 7.2v15.4\(3\)s2015-12-03
CVE-2015-6383 [HIGH] CWE-264 CVE-2015-6383: Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local use Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130.
nvd
CVE-2016-1432P4MEDIUMCVSS 6.5v3.15.0sv3.15.1s+1 more2016-06-18
CVE-2016-1432 [MEDIUM] CWE-399 CVE-2016-1432: Cisco IOS XE 3.15S and 3.16S on cBR-8 Converged Broadband Router devices allows remote authenticated Cisco IOS XE 3.15S and 3.16S on cBR-8 Converged Broadband Router devices allows remote authenticated users to cause a denial of service (NULL pointer dereference and card restart) via a crafted SNMP request, aka Bug ID CSCuu68862.
nvd
CVE-2016-1344P4MEDIUMCVSS 5.9v3.3s_3.3.0sv3.3s_3.3.1s+100 more2016-03-26
CVE-2016-1344 [MEDIUM] CWE-399 CVE-2016-1344: The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote at The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
nvd
CVE-2022-20727P4MEDIUMCVSS 6.7v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20727 [MEDIUM] CWE-22 CVE-2022-20727: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2017-12239P4MEDIUMCVSS 6.8v3.13.0asv3.13.0s+72 more2017-09-29
CVE-2017-12239 [MEDIUM] CWE-264 CVE-2017-12239: A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Ser A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system. The vulnerability exists because an engineering console port is available on the motherboard o
nvd
CVE-2020-3214P4MEDIUMCVSS 6.7v16.11.1v16.11.1a+11 more2020-06-03
CVE-2020-3214 [MEDIUM] CWE-264 CVE-2020-3214: A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate th A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to escalate their privileges to a user with root-level privileges. The vulnerability is due to insufficient validation of user-supplied content. This vulnerability could allow an attacker to load malicious software onto an affected device.
nvd
CVE-2019-12662P4MEDIUMCVSS 6.7v16.8.12019-09-25
CVE-2019-12662 [MEDIUM] CWE-347 CVE-2019-12662: A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, loca A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Op
nvd
CVE-2018-15374P4MEDIUMCVSS 6.7v16.6.12018-10-05
CVE-2018-15374 [MEDIUM] CWE-347 CVE-2018-15374: A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authentica A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software improperly verifying digital signatures for software images and files that are uploaded to a device. An attacker
nvd
CVE-2013-0149P4MEDIUMCVSS 5.8v2.1.0v2.1.1+60 more2013-08-05
CVE-2013-0149 [MEDIUM] CVE-2013-0149: The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9 The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (ro
nvd
CVE-2017-12272P4MEDIUMCVSS 6.1v16.1.2v16.2.0+1 more2017-10-19
CVE-2017-12272 [MEDIUM] CWE-79 CVE-2017-12272: A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, r A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected s
nvd
CVE-2021-1381P4MEDIUMCVSS 6.1v16.11.1v16.11.1a+34 more2021-03-24
CVE-2021-1381 [MEDIUM] CWE-489 CVE-2021-1381: A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high priv A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability is due to insufficient command authorization restrictions. An attacker could exploit this vulnerability by running commands on the ha
nvd
CVE-2020-3503P4MEDIUMCVSS 6.0v16.12.12020-09-24
CVE-2020-3503 [MEDIUM] CWE-284 CVE-2020-3503: A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permissions on an affected device. An attacker could exploit this vulnerability by connecting to an affected
nvd
CVE-2021-1394P4MEDIUMCVSS 5.3v16.10.1v16.10.1a+8 more2021-03-24
CVE-2021-1394 [MEDIUM] CWE-399 CVE-2021-1394: A vulnerability in the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergenc A vulnerability in the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the web management interface of an affected device. This vulnerability is due to incorrect processing of certain IPv4 TCP traffic
nvd
CVE-2018-0196P4MEDIUMCVSS 4.9v16.1.2v16.2.0+1 more2018-03-28
CVE-2018-0196 [MEDIUM] CWE-20 CVE-2018-0196: A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an aut A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to write arbitrary files to the operating system of an affected device. The vulnerability is due to insufficient input validation of HTTP requests that are sent to the web UI of the affected software. An attacker could exploit
nvd
CVE-2013-1143P4HIGHCVSS 7.1v3.1.0sv3.1.1s+17 more2013-03-28
CVE-2013-1143 [HIGH] CWE-119 CVE-2013-1143: The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3 The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory access and device reload) via a traffic engineering PATH message in an RSVP packet, aka Bug ID CSC
nvd
CVE-2017-12222P4MEDIUMCVSS 6.5v16.1.1v16.1.2+11 more2017-09-29
CVE-2017-12222 [MEDIUM] CWE-399 CVE-2017-12222: A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, a A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by submitting a crafted association request. A
nvd
CVE-2022-20684P4MEDIUMCVSS 6.5v3.15.1xbsv3.15.2xbs+88 more2022-04-15
CVE-2022-20684 [MEDIUM] CWE-190 CVE-2022-20684: A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition on the device. This vulnerab
nvd