cbcvebase.

Cisco IOS XE vulnerabilities

505 known vulnerabilities affecting cisco/ios_xe.

Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1

Vulnerabilities

Page 5 of 26
CVE-2024-20467P3HIGHCVSS 8.6v17.11.99swv17.12.1+1 more2024-09-25
CVE-2024-20467 [HIGH] CWE-399 CVE-2024-20467: A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Soft A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper management of resources during fragment reassembly. An attacker could exploit this vulnerabili
nvd
CVE-2024-20259P3HIGHCVSS 8.6v17.1.1v17.1.1a+78 more2024-03-27
CVE-2024-20259 [HIGH] CWE-122 CVE-2024-20259: A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a crafted IPv4 DHCP request packet being mishandled when endpoint analytics are enabled. An attacker cou
nvd
CVE-2024-20464P3HIGHCVSS 8.6v17.13.1v17.13.1a2024-09-25
CVE-2024-20464 [HIGH] CWE-20 CVE-2024-20464: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could a A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of received IPv4 PIMv2 packets. An attacker could exploit this vulnerability by sending a cr
nvd
CVE-2025-20154P3HIGHCVSS 8.6≥ 16.6.1, ≤ 17.2.32025-05-07
CVE-2025-20154 [HIGH] CWE-20 CVE-2025-20154: A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Softw A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could cause the ipsla_ippm_server proces
nvd
CVE-2021-1443P3HIGHCVSS 7.2v16.9.1v16.9.1a+59 more2021-03-24
CVE-2021-1443 [HIGH] CWE-77 CVE-2021-1443: A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software improperly sanitizes values that are parsed from a specific configuration file. An attacker cou
nvd
CVE-2018-0467P3HIGHCVSS 8.6v15.6\(2\)spv16.6.1+1 more2018-10-05
CVE-2018-0467 [HIGH] CWE-20 CVE-2018-0467: A vulnerability in the IPv6 processing code of Cisco IOS and IOS XE Software could allow an unauthen A vulnerability in the IPv6 processing code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect handling of specific IPv6 hop-by-hop options. An attacker could exploit this vulnerability by sending a malicious IPv6 packet to or through the affected device. A
nvd
CVE-2017-3860P3HIGHCVSS 8.6v3.2.1sgv3.2.8sg+22 more2017-04-20
CVE-2017-3860 [HIGH] CWE-119 CVE-2017-3860: Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisc Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafte
nvd
CVE-2017-3861P3HIGHCVSS 8.6v3.2.1sgv3.2.8sg+22 more2017-04-20
CVE-2017-3861 [HIGH] CWE-119 CVE-2017-3861: Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisc Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafte
nvd
CVE-2017-3863P3HIGHCVSS 8.6v3.2.1sgv3.2.8sg+22 more2017-04-20
CVE-2017-3863 [HIGH] CWE-119 CVE-2017-3863: Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisc Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafte
nvd
CVE-2017-3862P3HIGHCVSS 8.6v3.2.1sgv3.2.8sg+22 more2017-04-20
CVE-2017-3862 [HIGH] CWE-119 CVE-2017-3862: Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisc Multiple vulnerabilities in the EnergyWise module of Cisco IOS (12.2 and 15.0 through 15.6) and Cisco IOS XE (3.2 through 3.18) could allow an unauthenticated, remote attacker to cause a buffer overflow condition or a reload of an affected device, leading to a denial of service (DoS) condition. These vulnerabilities are due to improper parsing of crafte
nvd
CVE-2017-3864P3HIGHCVSS 8.6≥ 3.3, ≤ 3.72017-03-22
CVE-2017-3864 [HIGH] CWE-399 CVE-2017-3864: A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) a A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3 through 3.7) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability occurs during the parsing of a crafted DHCP packet. An attacker could exploit this vulnerability by sending c
nvd
CVE-2020-3225P3HIGHCVSS 8.6v3.3.0xov3.3.1xo+32 more2020-06-03
CVE-2020-3225 [HIGH] CWE-20 CVE-2020-3225: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature of Ci Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to insufficient input processing of CIP traffic.
nvd
CVE-2020-3414P3HIGHCVSS 8.6v16.9.2v16.10.4+3 more2020-09-24
CVE-2020-3414 [HIGH] CWE-19 CVE-2020-3414: A vulnerability in the packet processing of Cisco IOS XE Software for Cisco 4461 Integrated Services A vulnerability in the packet processing of Cisco IOS XE Software for Cisco 4461 Integrated Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect processing of IPv4 or IPv6 traffic to or through an affected device. An
nvd
CVE-2020-3228P3HIGHCVSS 8.6v3.3.0sev3.3.0xo+217 more2020-06-03
CVE-2020-3228 [HIGH] CWE-20 CVE-2020-3228: A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE So A vulnerability in Security Group Tag Exchange Protocol (SXP) in Cisco IOS Software, Cisco IOS XE Software, and Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because crafted SXP packets are mishandled. An attacker coul
nvd
CVE-2019-16009P3HIGHCVSS 8.8fixed in 16.1.12020-09-23
CVE-2019-16009 [HIGH] CWE-352 CVE-2019-16009: A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a us
nvd
CVE-2022-20683P3HIGHCVSS 8.6v3.15.1xbsv3.15.2xbs+99 more2022-04-15
CVE-2022-20683 [HIGH] CWE-124 CVE-2022-20683: A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software A vulnerability in the Application Visibility and Control (AVC-FNF) feature of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient packet verification for traffic inspected
nvd
CVE-2020-3510P3HIGHCVSS 8.6v16.12.1v16.12.2+1 more2020-09-24
CVE-2020-3510 [HIGH] CWE-388 CVE-2020-3510: A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 A vulnerability in the Umbrella Connector component of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to trigger a reload, resulting in a denial of service condition on an affected device. The vulnerability is due to insufficient error handling when parsing DNS requests. An attacker could ex
nvd
CVE-2020-3526P3HIGHCVSS 8.6v17.22020-09-24
CVE-2020-3526 [HIGH] CWE-20 CVE-2020-3526: A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cB A vulnerability in the Common Open Policy Service (COPS) engine of Cisco IOS XE Software on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to crash a device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a malformed COPS message to the device. A
nvd
CVE-2021-1611P3HIGHCVSS 8.6fixed in 17.3.12021-09-23
CVE-2021-1611 [HIGH] CWE-399 CVE-2021-1611: A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE Wireless Controller S A vulnerability in Ethernet over GRE (EoGRE) packet processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9800 Family Wireless Controller, Embedded Wireless Controller, and Embedded Wireless on Catalyst 9000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affecte
nvd
CVE-2024-20271P3HIGHCVSS 8.6fixed in 17.3.8≥ 17.4, < 17.6.6+2 more2024-03-27
CVE-2024-20271 [HIGH] CWE-20 CVE-2024-20271: A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unaut A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this vulnerability by sending a crafted IPv4 pac
nvd
Cisco IOS XE vulnerabilities | cvebase