cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 4 of 26
CVE-2017-12226P3HIGHCVSS 8.8v3.7.0ev3.7.1e+4 more2017-09-29
CVE-2017-12226 [HIGH] CWE-264 CVE-2017-12226: A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wir A vulnerability in the web-based Wireless Controller GUI of Cisco IOS XE Software for Cisco 5760 Wireless LAN Controllers, Cisco Catalyst 4500E Supervisor Engine 8-E (Wireless) Switches, and Cisco New Generation Wireless Controllers (NGWC) 3850 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnera
nvd
CVE-2019-1743P3HIGHCVSS 8.8v16.2.1v16.2.2+29 more2019-03-28
CVE-2019-1743 [HIGH] CWE-20 CVE-2019-1743: A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remot A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make unauthorized changes to the filesystem of the affected device. The vulnerability is due to improper input validation. An attacker could exploit this vulnerability by crafting a malicious file and uploading it to the device. An exploit co
nvd
CVE-2020-3425P3HIGHCVSS 8.8v16.1.1v16.1.2+105 more2020-09-24
CVE-2020-3425 [HIGH] CWE-20 CVE-2020-3425: Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an aut Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2020-3141P3HIGHCVSS 8.8v16.9.4v17.2.1+2 more2020-09-24
CVE-2020-3141 [HIGH] CWE-20 CVE-2020-3141: Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an aut Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2018-0195P3HIGHCVSS 8.8fixed in 16.2.22018-03-28
CVE-2018-0195 [HIGH] CWE-287 CVE-2018-0195: A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the API to perform privileged actions on an affected device. The vulnerability is due to insufficient authorization checks for requests that are sent to the REST API of the affected software. An attacker could exp
nvd
CVE-2020-3224P3HIGHCVSS 8.8v16.11.1v16.11.1a+4 more2020-06-03
CVE-2020-3224 [HIGH] CWE-77 CVE-2020-3224: A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an aut A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to inject IOS commands to an affected device. The injected commands should require a higher privilege level in order to be executed. The vulnerability is due to insufficient input validation of specific
nvd
CVE-2023-20186P3CRITICALCVSS 9.1v3.2.0sev3.2.1se+379 more2023-09-27
CVE-2023-20186 [CRITICAL] CWE-285 CVE-2023-20186: A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Soft A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect
nvd
CVE-2020-3400P3HIGHCVSS 8.8v16.2.2v16.3.1+13 more2020-09-24
CVE-2020-3400 [HIGH] CWE-862 CVE-2020-3400: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which they are not authorized.The vulnerability is due to insufficient authorization of web UI access requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web UI. A succ
nvd
CVE-2021-1433P3HIGHCVSS 8.1v3.15.1xbsv3.15.2xbs+21 more2021-03-24
CVE-2021-1433 [HIGH] CWE-119 CVE-2021-1433: A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticate A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic. An attacker could exploit this vulnerability by sending crafted traffic to the device. The at
nvd
CVE-2024-20437P3HIGHCVSS 8.8v17.3.2v17.3.2a+64 more2024-09-25
CVE-2024-20437 [HIGH] CWE-352 CVE-2024-20437: A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauth A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected devi
nvd
CVE-2019-1862P3HIGHCVSS 7.2v16.3.72019-05-13
CVE-2019-1862 [HIGH] CWE-20 CVE-2019-1862: A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an aut A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid administrat
nvd
CVE-2018-0164P3HIGHCVSS 8.6v15.6\(2\)sp2018-03-28
CVE-2018-0164 [HIGH] CWE-399 CVE-2018-0164: A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an u A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an interface queue wedge. The vulnerability is due to incorrect handling of crafted IPv6 packets. An attacker could exploit this vulnerability by sending crafted IPv6 packets through the device. An exploit could al
nvd
CVE-2020-3217P3HIGHCVSS 8.8v3.7.0ev3.7.1e+162 more2020-06-03
CVE-2020-3217 [HIGH] CWE-20 CVE-2020-3217: A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Sof A vulnerability in the Topology Discovery Service of Cisco One Platform Kit (onePK) in Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insuff
nvd
CVE-2020-3218P3HIGHCVSS 7.2v16.6.1v16.6.2+56 more2020-06-03
CVE-2020-3218 [HIGH] CWE-20 CVE-2020-3218: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by first creating a malicious
nvd
CVE-2024-20455P3HIGHCVSS 8.6v17.1.1v17.1.1a+85 more2024-09-25
CVE-2024-20455 [HIGH] CWE-371 CVE-2024-20455: A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense ( A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because UTD improperly handles certain packets as th
nvd
CVE-2019-1756P3HIGHCVSS 7.2v3.2.0jav16.7.1+12 more2019-03-28
CVE-2019-1756 [HIGH] CWE-20 CVE-2019-1756: A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute co A vulnerability in Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs because the affected software improperly sanitizes user-supplied input. An attacker who has valid administrator access to an affected device could exp
nvd
CVE-2020-3211P3HIGHCVSS 7.2v16.10.1v16.10.1a+14 more2020-06-03
CVE-2020-3211 [HIGH] CWE-77 CVE-2020-3211: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device. The vulnerability is due to improper input sanitization. An attacker who has valid administrative access to an affected device could exploit this
nvd
CVE-2020-3444P3HIGHCVSS 7.5≤ 16.12.2r≥ 17.2, ≤ 17.2.12020-11-06
CVE-2020-3444 [HIGH] CWE-20 CVE-2020-3444: A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthentic A vulnerability in the packet filtering features of Cisco SD-WAN Software could allow an unauthenticated, remote attacker to bypass L3 and L4 traffic filters. The vulnerability is due to improper traffic filtering conditions on an affected device. An attacker could exploit this vulnerability by crafting a malicious TCP packet with specific characteristic
nvd
CVE-2018-0470P3HIGHCVSS 8.6v16.2.0v16.3\(1\)2018-10-05
CVE-2018-0470 [HIGH] CWE-399 CVE-2018-0470: A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the affected software improperly parsing malformed HTTP packets that are destined to a device. An attacker
nvd
CVE-2020-3527P3HIGHCVSS 8.6≥ 16.9.0, < 16.9.5≥ 16.12.0, < 16.12.32020-09-24
CVE-2020-3527 [HIGH] CWE-20 CVE-2020-3527: A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthen A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device. The vulnerability is due to insufficient packet size validation. An attacker could exploit this vulnerability by sending jumbo frames or frames larger than the configured MTU size to the management interface of
nvd