Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
28
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 24 of 26
CVE-2013-5472HIGHCVSS 7.1v2.1.0v2.1.1+38 more2013-09-27
CVE-2013-5472 [HIGH] CWE-20 CVE-2013-5472: The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through
The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.
nvd
CVE-2013-0149MEDIUMCVSS 5.8v2.1.0v2.1.1+60 more2013-08-05
CVE-2013-0149 [MEDIUM] CVE-2013-0149: The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (ro
nvd
CVE-2013-2779HIGHCVSS 7.8v3.4.0asv3.4.0s+13 more2013-04-11
CVE-2013-2779 [HIGH] CVE-2013-2779: Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Servic
Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 MVPN (aka MVPNv6) packets, aka Bug ID CSCub34945, a different vu
nvd
CVE-2013-1164HIGHCVSS 7.8v3.4.0asv3.4.0s+5 more2013-04-11
CVE-2013-1164 [HIGH] CVE-2013-1164: Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does
Cisco IOS XE 3.4 before 3.4.4S, 3.5, and 3.6 on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) feature, which allows remote attackers to cause a denial of service (card reload) via fragmented IPv6 multicast packets, aka Bug ID CSCtz97563.
nvd
CVE-2013-1167HIGHCVSS 7.1v3.2.00.xo.15.0\(2\)xov3.2.0s+21 more2013-04-11
CVE-2013-1167 [HIGH] CWE-22 CVE-2013-1167: Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (AS
Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled during the processing of encapsulation, aka Bug ID CSCtt11558.
nvd
CVE-2013-1165HIGHCVSS 7.8≤ 3.4.3sv2.1.0+29 more2013-04-11
CVE-2013-1165 [HIGH] CWE-20 CVE-2013-1165: Cisco IOS XE 2.x and 3.x before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregatio
Cisco IOS XE 2.x and 3.x before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) allows remote attackers to cause a denial of service (card reload) by sending many crafted L2TP packets, aka Bug ID CSCtz23293.
nvd
CVE-2013-1166HIGHCVSS 7.8v3.2.0sv3.2.1s+11 more2013-04-11
CVE-2013-1166 [HIGH] CWE-20 CVE-2013-1166: Cisco IOS XE 3.2 through 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggreg
Cisco IOS XE 3.2 through 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR), when VRF-aware NAT and SIP ALG are enabled, allows remote attackers to cause a denial of service (card reload) by sending many SIP packets, aka Bug ID CSCuc65609.
nvd
CVE-2013-1143HIGHCVSS 7.1v3.1.0sv3.1.1s+17 more2013-03-28
CVE-2013-1143 [HIGH] CWE-119 CVE-2013-1143: The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3
The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory access and device reload) via a traffic engineering PATH message in an RSVP packet, aka Bug ID CSC
nvd
CVE-2013-1148HIGHCVSS 7.8v3.1.0sv3.1.1s+17 more2013-03-28
CVE-2013-1148 [HIGH] CWE-119 CVE-2013-1148: The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15
The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S allows remote attackers to cause a denial of service (device reload) via crafted (1) IPv4 or (2) IPv6 IP SLA packets on UDP port 1167, aka Bug ID CSCuc72594.
nvd
CVE-2012-4617HIGHCVSS 7.1v3.5.0sv3.5.1s2012-09-27
CVE-2012-4617 [HIGH] CWE-20 CVE-2012-4617: The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.
The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
nvd
CVE-2012-4622HIGHCVSS 7.1v3.2.00.xo.15.0\(2\)xo2012-09-27
CVE-2012-4622 [HIGH] CWE-399 CVE-2012-4622: Cisco IOS XE 03.02.00.XO.15.0(2)XO on Catalyst 4500E series switches, when a Supervisor Engine 7L-E
Cisco IOS XE 03.02.00.XO.15.0(2)XO on Catalyst 4500E series switches, when a Supervisor Engine 7L-E card is installed, allows remote attackers to cause a denial of service (card reload) via malformed packets that trigger uncorrected ECC error messages, aka Bug ID CSCty88456.
nvd
CVE-2012-4623HIGHCVSS 7.8v2.1v2.1.0+43 more2012-09-27
CVE-2012-4623 [HIGH] CWE-20 CVE-2012-4623: The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.
The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723.
nvd
CVE-2012-3949HIGHCVSS 7.8v3.3.0sgv3.3.1s+11 more2012-09-27
CVE-2012-3949 [HIGH] CWE-20 CVE-2012-3949: The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5,
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a cra
nvd
CVE-2011-4231MEDIUMCVSS 6.3v3.1.0sv3.1.0sg+21 more2012-05-03
CVE-2011-4231 [MEDIUM] CWE-20 CVE-2011-4231: Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in u
Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.
nvd
CVE-2011-4007MEDIUMCVSS 5.4v3.1.0sv3.1.0sg+17 more2012-05-02
CVE-2011-4007 [MEDIUM] CWE-20 CVE-2011-4007: Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition"
Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka Bug ID CSCtr56576.
nvd
CVE-2012-0382HIGHCVSS 7.5≥ 2.1.0, ≤ 2.6.2≥ 3.1.0s, < 3.4.1s+1 more2012-03-29
CVE-2012-0382 [HIGH] CWE-400 CVE-2012-0382: The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4,
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug I
nvd
CVE-2012-0381HIGHCVSS 7.5≥ 2.1.0, ≤ 2.6.2≥ 3.1.0s, < 3.4.1s+1 more2012-03-29
CVE-2012-0381 [HIGH] CWE-310 CVE-2012-0381: The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x throu
The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.
nvd
CVE-2012-0384HIGHCVSS 7.2v2.1v2.1.0+34 more2012-03-29
CVE-2012-0384 [HIGH] CWE-269 CVE-2012-0384: Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2)
nvd
CVE-2012-0386HIGHCVSS 7.8v2.3v2.3.0+27 more2012-03-29
CVE-2012-0386 [HIGH] CWE-310 CVE-2012-0386: The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.
The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.
nvd
CVE-2012-1311HIGHCVSS 7.8v3.2.0sv3.2.1s+3 more2012-03-29
CVE-2012-1311 [HIGH] CWE-399 CVE-2012-1311: The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a V
The RSVP feature in Cisco IOS 15.0 and 15.1 and IOS XE 3.2.xS through 3.4.xS before 3.4.2S, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge and service outage) via crafted RSVP packets, aka Bug ID CSCts80643.
nvd