Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
28
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 4 of 26
CVE-2023-20235HIGHCVSS 8.8fixed in 17.3.12023-10-04
CVE-2023-20235 [HIGH] CWE-552 CVE-2023-20235: A vulnerability in the on-device application development workflow feature for the Cisco IOx applicat A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability exists because Docker containers with the privileged runtime option are not
nvd
CVE-2023-20186CRITICALCVSS 9.1v3.2.0sev3.2.1se+379 more2023-09-27
CVE-2023-20186 [CRITICAL] CWE-285 CVE-2023-20186: A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Soft A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect
nvd
CVE-2023-20231HIGHCVSS 8.8v16.12.4v16.12.4a+65 more2023-09-27
CVE-2023-20231 [HIGH] CWE-78 CVE-2023-20231: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI. A successful exploit could allow the attacker to
nvd
CVE-2023-20033HIGHCVSS 8.6v16.3.1v16.3.1a+56 more2023-09-27
CVE-2023-20033 [HIGH] CWE-770 CVE-2023-20033: A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches c A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when processing traffic that is received on th
nvd
CVE-2023-20227HIGHCVSS 7.5v16.8.1v16.8.1a+94 more2023-09-27
CVE-2023-20227 [HIGH] CWE-388 CVE-2023-20227: A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allo A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packet
nvd
CVE-2023-20226HIGHCVSS 7.5v17.7.1v17.7.1a+9 more2023-09-27
CVE-2023-20226 [HIGH] CWE-456 CVE-2023-20226: A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Ci A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the
nvd
CVE-2023-20187HIGHCVSS 7.5v3.7.1sv3.7.2s+199 more2023-09-27
CVE-2023-20187 [HIGH] CWE-823 CVE-2023-20187: A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software fo A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect handling of certain IPv
nvd
CVE-2023-20109MEDIUMCVSS 6.6KEVv3.3.0sgv3.3.1sg+362 more2023-09-27
CVE-2023-20109 [MEDIUM] CWE-787 CVE-2023-20109: A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software a A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to i
nvd
CVE-2023-20202MEDIUMCVSS 6.5v17.9.1v17.9.1a+10 more2023-09-27
CVE-2023-20202 [MEDIUM] CWE-789 CVE-2023-20202: A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless A vulnerability in the Wireless Network Control daemon (wncd) of Cisco IOS XE Software for Wireless LAN Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper memory management. An attacker could exploit this vulnerability by sending a series of network request
nvd
CVE-2023-20029HIGHCVSS 7.8v17.7.1v17.8.12023-03-23
CVE-2023-20029 [HIGH] CWE-122 CVE-2023-20029: A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticat A vulnerability in the Meraki onboarding feature of Cisco IOS XE Software could allow an authenticated, local attacker to gain root level privileges on an affected device. This vulnerability is due to insufficient memory protection in the Meraki onboarding feature of an affected device. An attacker could exploit this vulnerability by modifying the Mer
nvd
CVE-2023-20080HIGHCVSS 7.5v3.3.0xov3.3.1xo+363 more2023-03-23
CVE-2023-20080 [HIGH] CWE-129 CVE-2023-20080: A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS X A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries. An attacker could exploit this vulnerability by sending crafted DHCPv6 me
nvd
CVE-2023-20072HIGHCVSS 8.6v17.9.1v17.9.1a+1 more2023-03-23
CVE-2023-20072 [HIGH] CWE-20 CVE-2023-20072: A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Softwa A vulnerability in the fragmentation handling code of tunnel protocol packets in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected system to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of large fragmented tunnel protocol packets. One example of a t
nvd
CVE-2023-20027HIGHCVSS 8.6v3.9.0asv3.9.1s+188 more2023-03-23
CVE-2023-20027 [HIGH] CWE-416 CVE-2023-20027: A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel
nvd
CVE-2023-20065HIGHCVSS 7.8v17.6.3v17.11.12023-03-23
CVE-2023-20065 [HIGH] CWE-284 CVE-2023-20065: A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Ci
nvd
CVE-2023-20066MEDIUMCVSS 6.5v16.12.3v17.3.2+1 more2023-03-23
CVE-2023-20066 [MEDIUM] CWE-23 CVE-2023-20066: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security configuration. An attacker could exploit this vulnerability by sending a crafted requ
nvd
CVE-2023-20097MEDIUMCVSS 6.7fixed in 16.12.8≥ 17.1, < 17.3.6+2 more2023-03-23
CVE-2023-20097 [MEDIUM] CWE-77 CVE-2023-20097: A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that are issued from a wireless controller to an AP. An attacker with Administrator access to the CLI of the controller
nvd
CVE-2023-20056MEDIUMCVSS 5.5fixed in 16.12.8≥ 17.1, < 17.3.6+2 more2023-03-23
CVE-2023-20056 [MEDIUM] CWE-78 CVE-2023-20056: A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticat A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of commands supplied by the user. An attacker could exploit this vulnerability by authenticating to a devi
nvd
CVE-2023-20100MEDIUMCVSS 6.8v17.10.12023-03-23
CVE-2023-20100 [MEDIUM] CWE-694 CVE-2023-20100: A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points (CAPWAP) protocol of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic erro
nvd
CVE-2023-20082MEDIUMCVSS 6.8fixed in 17.3.7≥ 17.4, < 17.6.5+1 more2023-03-23
CVE-2023-20082 [MEDIUM] CWE-78 CVE-2023-20082: A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an auth A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to errors that occur when retrieving th
nvd
CVE-2023-20081MEDIUMCVSS 5.9v17.8.12023-03-23
CVE-2023-20081 [MEDIUM] CWE-122 CVE-2023-20081: A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) S A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu
nvd