cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 23 of 26
CVE-2023-20067P4MEDIUMCVSS 6.5v16.10.1v16.10.1e+46 more2023-03-23
CVE-2023-20067 [MEDIUM] CWE-770 CVE-2023-20067: A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN A vulnerability in the HTTP-based client profiling feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit this vu
nvd
CVE-2018-0188P4MEDIUMCVSS 6.1fixed in 16.3.62018-03-28
CVE-2018-0188 [MEDIUM] CWE-79 CVE-2018-0188: Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities are due to insufficient input validation of certain parameters that are passed to the affecte
nvd
CVE-2018-0186P4MEDIUMCVSS 6.1fixed in 16.3.62018-03-28
CVE-2018-0186 [MEDIUM] CWE-79 CVE-2018-0186: Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities are due to insufficient input validation of certain parameters that are passed to the affecte
nvd
CVE-2018-0190P4MEDIUMCVSS 6.1fixed in 16.3.62018-03-28
CVE-2018-0190 [MEDIUM] CWE-79 CVE-2018-0190: Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities are due to insufficient input validation of certain parameters that are passed to the affecte
nvd
CVE-2012-4617P4HIGHCVSS 7.1v3.5.0sv3.5.1s2012-09-27
CVE-2012-4617 [HIGH] CWE-20 CVE-2012-4617: The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2. The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
nvd
CVE-2024-20324P4MEDIUMCVSS 5.5v16.10.1v16.10.1e+58 more2024-03-27
CVE-2024-20324 [MEDIUM] CWE-274 CVE-2024-20324: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, lo A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords. This vulnerability is due to improper privilege checks. An attacker could exploit this vulnerability by using the show and show tech wireless CLI commands to access configuration d
nvd
CVE-2012-4622P4HIGHCVSS 7.1v3.2.00.xo.15.0\(2\)xo2012-09-27
CVE-2012-4622 [HIGH] CWE-399 CVE-2012-4622: Cisco IOS XE 03.02.00.XO.15.0(2)XO on Catalyst 4500E series switches, when a Supervisor Engine 7L-E Cisco IOS XE 03.02.00.XO.15.0(2)XO on Catalyst 4500E series switches, when a Supervisor Engine 7L-E card is installed, allows remote attackers to cause a denial of service (card reload) via malformed packets that trigger uncorrected ECC error messages, aka Bug ID CSCty88456.
nvd
CVE-2014-3269P4MEDIUMCVSS 6.8v3.5e2014-05-20
CVE-2014-3269 [MEDIUM] CWE-20 CVE-2014-3269: The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.
nvd
CVE-2014-2183P4MEDIUMCVSS 6.3≤ 3.10.2sv3.10+3 more2014-04-29
CVE-2014-2183 [MEDIUM] CWE-20 CVE-2014-2183: The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticate The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.
nvd
CVE-2020-3429P4MEDIUMCVSS 6.5v16.12.1s2020-09-24
CVE-2020-3429 [MEDIUM] CWE-20 CVE-2020-3429: A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Sof A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect packet processing during the WPA2 and WPA3 authentication h
nvd
CVE-2019-1746P4MEDIUMCVSS 6.5v3.2.0sgv3.2.1sg+91 more2019-03-28
CVE-2019-1746 [MEDIUM] CWE-20 CVE-2019-1746: A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and C A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation when processing CMP management packets. An attacker cou
nvd
CVE-2018-0197P4MEDIUMCVSS 6.5v3.2.0jav3.2.0se+132 more2018-10-05
CVE-2018-0197 [MEDIUM] CWE-20 CVE-2018-0197: A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to corrupt the internal VTP database on an affected device and cause a denial of service (DoS) condition. The vulnerability is due to a logic error in how the affected software handles a subset
nvd
CVE-2017-6665P4MEDIUMCVSS 6.5v3.7.0ev3.7.1e+68 more2017-08-07
CVE-2017-6665 [MEDIUM] CWE-319 CVE-2017-6665: A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to reset the Autonomic Control Plane (ACP) of an affected system and view ACP packets that are transferred in clear text within an affected system, an Information Disclosure Vulnerability. More Informatio
nvd
CVE-2021-1352P4MEDIUMCVSS 6.5v16.4.1v16.4.2+87 more2021-03-24
CVE-2021-1352 [MEDIUM] CWE-823 CVE-2021-1352: A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software c A vulnerability in the DECnet Phase IV and DECnet/OSI protocol processing of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of DECnet traffic that is received by an affected device. An attacker could ex
nvd
CVE-2023-20202P4MEDIUMCVSS 6.5v17.9.1v17.9.1a+10 more2023-09-27
CVE-2023-20202 [MEDIUM] CWE-789 CVE-2023-20202: A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network request
nvd
CVE-2022-20724P4MEDIUMCVSS 5.3v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20724 [MEDIUM] CWE-22 CVE-2022-20724: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2020-3465P4MEDIUMCVSS 6.5v16.6.9v17.4.12020-09-24
CVE-2020-3465 [MEDIUM] CWE-20 CVE-2020-3465: A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a device to reload. The vulnerability is due to incorrect handling of certain valid, but not typical, Ethernet frames. An attacker could exploit this vulnerability by sending the Ethernet frames onto the Ethernet segment. A successful exploit could allow
nvd
CVE-2013-6692P4MEDIUMCVSS 6.3≤ 3.8s\(.2\)v3.7.0s+5 more2013-11-22
CVE-2013-6692 [MEDIUM] CWE-399 CVE-2013-6692: Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP addre Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a denial of service (device reload) via an AAA packet that triggers an address requirement, aka Bug ID CSCuh04949.
nvd
CVE-2013-6981P4MEDIUMCVSS 5.4≤ 3.7s\(.1\)v2.5\(.0\)+27 more2013-12-28
CVE-2013-6981 [MEDIUM] CWE-20 CVE-2013-6981: Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Proce Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.
nvd
CVE-2018-0189P4MEDIUMCVSS 5.3fixed in 15.5\(3\)s5fixed in 15.5\(3\)m5+8 more2018-03-28
CVE-2018-0189 [MEDIUM] CWE-399 CVE-2018-0189: A vulnerability in the Forwarding Information Base (FIB) code of Cisco IOS Software and Cisco IOS XE A vulnerability in the Forwarding Information Base (FIB) code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, network attacker to cause a denial of service (DoS) condition. The vulnerability is due to a limitation in the way the FIB is internally representing recursive routes. An attacker could exploit this vulnerabilit
nvd
Cisco IOS XE vulnerabilities | cvebase