Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 25 of 26
CVE-2025-20195P4MEDIUMCVSS 4.3v16.1.1v16.1.2+208 more2025-05-07
CVE-2025-20195 [MEDIUM] CWE-352 CVE-2025-20195: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauth
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a CSRF attack and execute commands on the CLI of an affected device.
This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could expl
nvd
CVE-2015-6294P4MEDIUMCVSS 6.1v3.6e.0v3.6e.1+1 more2015-09-18
CVE-2015-6294 [MEDIUM] CWE-399 CVE-2015-6294: Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a deni
Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770.
nvd
CVE-2011-3274P4MEDIUMCVSS 6.1v2.1.0v2.1.1+27 more2011-10-03
CVE-2011-3274 [MEDIUM] CVE-2011-3274: Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x
Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device crash) via a crafted IPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCto07919.
nvd
CVE-2020-3201P4MEDIUMCVSS 6.0v3.2.0sgv3.2.1sg+245 more2020-06-03
CVE-2020-3201 [MEDIUM] CWE-20 CVE-2020-3201: A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS X
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter.
nvd
CVE-2011-4007P4MEDIUMCVSS 5.4v3.1.0sv3.1.0sg+17 more2012-05-02
CVE-2011-4007 [MEDIUM] CWE-20 CVE-2011-4007: Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition"
Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka Bug ID CSCtr56576.
nvd
CVE-2024-20309P4MEDIUMCVSS 5.5v3.2.0sev3.2.1se+341 more2024-03-27
CVE-2024-20309 [MEDIUM] CWE-828 CVE-2024-20309: A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow
A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding.
This vulnerability is due to the incorrect handling of specific ingress traffic when flow control hardware is enabled on the AUX port. An attacker could exploit
nvd
CVE-2020-3206P4MEDIUMCVSS 4.7v16.10.1v16.10.1e+1 more2020-06-03
CVE-2020-3206 [MEDIUM] CWE-20 CVE-2020-3206: A vulnerability in the handling of IEEE 802.11w Protected Management Frames (PMFs) of Cisco Catalyst
A vulnerability in the handling of IEEE 802.11w Protected Management Frames (PMFs) of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device. The vulnerability exists because the affected software does not properl
nvd
CVE-2021-1436P4MEDIUMCVSS 4.4v3.15.1xbsv3.15.2xbs+35 more2021-03-24
CVE-2021-1436 [MEDIUM] CWE-22 CVE-2021-1436: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request
nvd
CVE-2020-3222P4MEDIUMCVSS 4.3v16.10.1v16.10.1a+20 more2020-06-03
CVE-2020-3222 [MEDIUM] CWE-17 CVE-2020-3222: A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an una
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an affected device. The vulnerability is due to the presence of a proxy service at a specific endpoint of the web UI. An attacker could exploit this vulnerability by connecting to t
nvd
CVE-2015-0708P4MEDIUMCVSS 6.1v3.13s.0v3.13s.1+1 more2015-04-29
CVE-2015-0708 [MEDIUM] CWE-399 CVE-2015-0708: Cisco IOS 15.4S, 15.4SN, and 15.5S and IOS XE 3.13S and 3.14S allow remote attackers to cause a deni
Cisco IOS 15.4S, 15.4SN, and 15.5S and IOS XE 3.13S and 3.14S allow remote attackers to cause a denial of service (device crash) by including an IA_NA option in a DHCPv6 Solicit message on the local network, aka Bug ID CSCur29956.
nvd
CVE-2014-3290P4MEDIUMCVSS 4.8v3.12s2014-06-14
CVE-2014-3290 [MEDIUM] CWE-264 CVE-2014-3290: The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking,
The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.
nvd
CVE-2019-12668P4MEDIUMCVSS 4.8≥ 16.1.1, < 16.3.8≥ 16.4.1, < 16.6.5+8 more2019-09-25
CVE-2019-12668 [MEDIUM] CWE-79 CVE-2019-12668: A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an auth
A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software using the banner parameter. The vulnerability is due to insufficient input validation of the banner parameters
nvd
CVE-2019-12667P4MEDIUMCVSS 4.8≥ 16.1.1, < 16.6.5≥ 16.7.1, < 16.9.22019-09-25
CVE-2019-12667 [MEDIUM] CWE-79 CVE-2019-12667: A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, rem
A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affec
nvd
CVE-2022-20725P4MEDIUMCVSS 4.8v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20725 [MEDIUM] CWE-22 CVE-2022-20725: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2020-3418P4MEDIUMCVSS 4.7v17.1.12020-09-24
CVE-2020-3418 [MEDIUM] CWE-284 CVE-2020-3418: A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers
A vulnerability in Cisco IOS XE Wireless Controller Software for Cisco Catalyst 9800 Series Routers could allow an unauthenticated, adjacent attacker to send ICMPv6 traffic prior to the client being placed into RUN state. The vulnerability is due to an incomplete access control list (ACL) being applied prior to RUN state. An attacker could exploit this
nvd
CVE-2021-1356P4MEDIUMCVSS 4.3v3.15.1xbsv3.15.2xbs+11 more2021-03-24
CVE-2021-1356 [MEDIUM] CWE-20 CVE-2021-1356: Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient error handling in the web UI. An attac
nvd
CVE-2021-1220P4MEDIUMCVSS 4.3v3.15.1xbsv3.15.2xbs+33 more2021-03-24
CVE-2021-1220 [MEDIUM] CWE-20 CVE-2021-1220: Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These vulnerabilities are due to insufficient error handling in the web UI. An attac
nvd
CVE-2014-7990P4MEDIUMCVSS 6.8≤ 3.5e2014-11-07
CVE-2014-7990 [MEDIUM] CWE-20 CVE-2014-7990: Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815.
nvd
CVE-2024-20434P4MEDIUMCVSS 4.3v16.6.1v16.6.2+89 more2024-09-25
CVE-2024-20434 [MEDIUM] CWE-190 CVE-2024-20434: A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device.
This vulnerability is due to improper handling of frames with VLAN tag information. An attacker could exploit this vulnerability by sending crafted frames to an affected de
nvd
CVE-2021-1374P4MEDIUMCVSS 4.8v16.6.1v16.6.2+87 more2021-03-24
CVE-2021-1374 [MEDIUM] CWE-79 CVE-2021-1374: A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software f
A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software for the Catalyst 9000 Family of switches could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the web-based management interface of an affected device. The vulnerability is due to insufficien
nvd