Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 26 of 26
CVE-2021-27853P4MEDIUMCVSS 4.7v17.3.3v15.2\(07\)e02+3 more2022-09-27
CVE-2021-27853 [MEDIUM] CWE-290 CVE-2021-27853: Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed using combinations of VLAN 0 headers and LLC/SNAP headers.
nvd
CVE-2018-0257P4MEDIUMCVSS 4.3≥ 3.18, ≤ 3.18.4≥ 16.6, ≤ 16.6.3+4 more2018-04-19
CVE-2018-0257 [MEDIUM] CWE-399 CVE-2018-0257: A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers cou
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the incorrect handling of certain DHCP packets. An attacker could exploit this vu
nvd
CVE-2019-1761P4MEDIUMCVSS 4.3v3.2.0jav3.2.0se+269 more2019-03-28
CVE-2019-1761 [MEDIUM] CWE-665 CVE-2019-1761: A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software
A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficient memory initialization. An attacker could exploit this vulnerability by receiving HSRPv2 tra
nvd
CVE-2019-1762P4MEDIUMCVSS 4.4v16.6.1v16.6.2+26 more2019-03-28
CVE-2019-1762 [MEDIUM] CWE-200 CVE-2019-1762: A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authen
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed at encryption time, when affected software handles configuration updates. An attacker could exploit th
nvd
CVE-2016-6450P4LOWCVSS 2.5v3.6.2aev3.6.3e+8 more2016-11-19
CVE-2016-6450 [LOW] CWE-20 CVE-2016-6450: A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticate
A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticated, local attacker to gain write access to some files in the underlying operating system. This vulnerability affects the following products if they are running a vulnerable release of Cisco IOS XE Software: Cisco 5700 Series Wireless LAN Controllers, Cisco C
nvd
← Previous26 / 26