cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 24 of 26
CVE-2019-12660P4MEDIUMCVSS 5.5≥ 16.1.12019-09-25
CVE-2019-12660 [MEDIUM] CWE-668 CVE-2019-12660: A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authentica
nvd
CVE-2022-20722P4MEDIUMCVSS 4.9v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20722 [MEDIUM] CWE-22 CVE-2022-20722: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2022-20721P4MEDIUMCVSS 4.9v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20721 [MEDIUM] CWE-22 CVE-2022-20721: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2021-1616P4MEDIUMCVSS 4.7fixed in 17.6.12021-09-23
CVE-2021-1616 [MEDIUM] CWE-693 CVE-2021-1616: A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation A vulnerability in the H.323 application level gateway (ALG) used by the Network Address Translation (NAT) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass the ALG. This vulnerability is due to insufficient data validation of traffic that is traversing the ALG. An attacker could exploit this vulnerability by s
nvd
CVE-2020-3516P4MEDIUMCVSS 4.3fixed in 16.9.6≥ 16.12.0, < 16.12.2+2 more2020-09-24
CVE-2020-3516 [MEDIUM] CWE-20 CVE-2020-3516: A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticat A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this vulnerability by entering unexpected characters during a valid authentication. A su
nvd
CVE-2018-0466P4MEDIUMCVSS 6.5v16.2.12018-10-05
CVE-2018-0466 [MEDIUM] CWE-399 CVE-2018-0466: A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and I A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. The vulnerability is due to incorrect handling of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending crafted OSPFv3 Lin
nvd
CVE-2012-5723P4MEDIUMCVSS 6.1≤ 3.7s\(.1\)v3.6.0s+9 more2014-04-24
CVE-2012-5723 [MEDIUM] CWE-20 CVE-2012-5723: Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attacker Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.
nvd
CVE-2009-2049P4MEDIUMCVSS 5.4v2.3v2.3.1t+2 more2009-07-30
CVE-2009-2049 [MEDIUM] CWE-16 CVE-2009-2049: Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12. Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1 through 12.2(33)SXI2, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of
nvd
CVE-2015-4293P4MEDIUMCVSS 5.0v2.1.0v2.1.1+27 more2015-07-30
CVE-2015-4293 [MEDIUM] CWE-399 CVE-2015-4293: The packet-reassembly implementation in Cisco IOS XE 3.13S and earlier allows remote attackers to ca The packet-reassembly implementation in Cisco IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (CPU consumption or packet loss) via fragmented (1) IPv4 or (2) IPv6 packets that trigger ATTN-3-SYNC_TIMEOUT errors after reassembly failures, aka Bug ID CSCuo37957.
nvd
CVE-2015-6429P4MEDIUMCVSS 5.0v3.15s.0v3.15s.1+5 more2015-12-19
CVE-2015-6429 [MEDIUM] CWE-19 CVE-2015-6429: The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote at The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.
nvd
CVE-2015-4243P4MEDIUMCVSS 6.1v3.5.0s2015-07-08
CVE-2015-4243 [MEDIUM] CWE-399 CVE-2015-4243: The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote atta The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty94202.
nvd
CVE-2015-0710P4MEDIUMCVSS 6.1v3.10.0sv3.10s.012015-04-29
CVE-2015-0710 [MEDIUM] CWE-399 CVE-2015-0710: The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attack The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs CSCup37676 and CSCup30335.
nvd
CVE-2018-0480P4MEDIUMCVSS 6.1v3.6\(5\)2018-10-05
CVE-2018-0480 [MEDIUM] CWE-362 CVE-2018-0480: A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthent A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition. The vulnerability is due to a race condition that occurs when the VLAN and port enter an errdisabled state, resulting in an incorrect state in the so
nvd
CVE-2016-1459P4MEDIUMCVSS 5.3v3.13.2sv3.13.3s+17 more2016-07-17
CVE-2016-1459 [MEDIUM] CWE-399 CVE-2016-1459: Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users t Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via crafted attributes in a BGP message, aka Bug ID CSCuz21061.
nvd
CVE-2025-20214P4MEDIUMCVSS 4.3v17.11.1v17.11.1a+12 more2025-05-07
CVE-2025-20214 [MEDIUM] CWE-639 CVE-2025-20214: A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software c A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a subtle change in inner API call behavior causes results to be filtered incorrectly. An attacker c
nvd
CVE-2015-6431P4MEDIUMCVSS 6.5v16.1.12015-12-23
CVE-2015-6431 [MEDIUM] CWE-399 CVE-2015-6431: Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packe Cisco IOS XE 16.1.1 allows remote attackers to cause a denial of service (device reload) via a packet with the 00-00-00-00-00-00 source MAC address, aka Bug ID CSCux48405.
nvd
CVE-2011-4231P4MEDIUMCVSS 6.3v3.1.0sv3.1.0sg+21 more2012-05-03
CVE-2011-4231 [MEDIUM] CWE-20 CVE-2011-4231: Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in u Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.
nvd
CVE-2014-3409P4MEDIUMCVSS 6.1≤ 3.13s2014-10-25
CVE-2014-3409 [MEDIUM] CWE-399 CVE-2014-3409: The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and ear The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (device reload) via malformed CFM packets, aka Bug ID CSCuq93406.
nvd
CVE-2023-20056P4MEDIUMCVSS 5.5fixed in 16.12.8≥ 17.1, < 17.3.6+2 more2023-03-23
CVE-2023-20056 [MEDIUM] CWE-78 CVE-2023-20056: A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticat A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a devi
nvd
CVE-2017-6770P4MEDIUMCVSS 4.2v3.6.0ev3.6.1e+46 more2017-08-07
CVE-2017-6770 [MEDIUM] CWE-20 CVE-2017-6770: Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an unauthenticated, remote attacker to t
nvd