Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 7 of 26
CVE-2019-1737P3HIGHCVSS 8.6v3.2.0sev3.2.1se+193 more2019-03-27
CVE-2019-1737 [HIGH] CWE-400 CVE-2019-1737: A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software
A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE software could allow an unauthenticated, remote attacker to cause an interface wedge and an eventual denial of service (DoS) condition on the affected device. The vulnerability is due to improper socket resources handling in the IP SLA res
nvd
CVE-2020-3226P3HIGHCVSS 8.6v3.10.0sv3.10.1s+155 more2020-06-03
CVE-2020-3226 [HIGH] CWE-20 CVE-2020-3226: A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS
A vulnerability in the Session Initiation Protocol (SIP) library of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient sanity checks on received SIP messages. An attacker could exp
nvd
CVE-2020-3221P3HIGHCVSS 8.6v16.10.1v16.10.1a+14 more2020-06-03
CVE-2020-3221 [HIGH] CWE-20 CVE-2020-3221: A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisc
A vulnerability in the Flexible NetFlow Version 9 packet processor of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper validation of parameters in a Flexible NetFlow Version 9 re
nvd
CVE-2021-1373P3HIGHCVSS 8.6v16.10.1v16.10.1e+23 more2021-03-24
CVE-2021-1373 [HIGH] CWE-126 CVE-2021-1373: A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processi
A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of an affected device. The vulnerability is due to insuffi
nvd
CVE-2020-3509P3HIGHCVSS 8.6v16.7\(1\)2020-09-24
CVE-2020-3509 [HIGH] CWE-388 CVE-2020-3509: A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broad
A vulnerability in the DHCP message handler of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause the supervisor to crash, which could result in a denial of service (DoS) condition. The vulnerability is due to insufficient error handling when DHCP version 4 (DHCPv4) messages are par
nvd
CVE-2021-34697P3HIGHCVSS 8.6≥ 17.3.1, < 17.3.32021-09-23
CVE-2021-34697 [HIGH] CWE-665 CVE-2021-34697: A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS
A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is due to incorrect programming of the half-opened connections limit, TCP SYN flood limit, or T
nvd
CVE-2023-20027P3HIGHCVSS 8.6v3.9.0asv3.9.1s+188 more2023-03-23
CVE-2023-20027 [HIGH] CWE-416 CVE-2023-20027: A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of
A vulnerability in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper reassembly of large packets that occurs when VFR is enabled on either a tunnel
nvd
CVE-2023-20033P3HIGHCVSS 8.6v16.3.1v16.3.1a+56 more2023-09-27
CVE-2023-20033 [HIGH] CWE-770 CVE-2023-20033: A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches c
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to improper resource management when processing traffic that is received on th
nvd
CVE-2019-12664P3HIGHCVSS 7.5v16.6.42019-09-25
CVE-2019-12664 [HIGH] CWE-200 CVE-2019-12664: A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Ci
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to successful PPP authentication. The vulnerability is due to insufficient validation of the state of
nvd
CVE-2025-20172P3HIGHCVSS 7.7v3.2.0sev3.2.1se+424 more2025-02-05
CVE-2025-20172 [HIGH] CWE-248 CVE-2025-20172: A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR
A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted S
nvd
CVE-2022-20693P3HIGHCVSS 7.2v3.15.1xbsv3.15.2xbs+61 more2022-04-15
CVE-2022-20693 [HIGH] CWE-74 CVE-2022-20693: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI API. A successful exploit could allow the a
nvd
CVE-2022-20851P3HIGHCVSS 7.2v17.6.12022-09-30
CVE-2022-20851 [HIGH] CWE-77 CVE-2022-20851: A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web UI API. A successful exploit could allow the a
nvd
CVE-2021-1622P3HIGHCVSS 8.6fixed in 16.12.1z1v17.3.1x2021-09-23
CVE-2021-1622 [HIGH] CWE-833 CVE-2021-1622: A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Co
A vulnerability in the Common Open Policy Service (COPS) of Cisco IOS XE Software for Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause resource exhaustion, resulting in a denial of service (DoS) condition. This vulnerability is due to a deadlock condition in the code when processing COPS packets under cert
nvd
CVE-2025-20171P3HIGHCVSS 7.7v3.2.0sev3.2.0sg+450 more2025-02-05
CVE-2025-20171 [HIGH] CWE-248 CVE-2025-20171: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20170P3HIGHCVSS 7.7v3.2.0sev3.2.0sg+444 more2025-02-05
CVE-2025-20170 [HIGH] CWE-805 CVE-2025-20170: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20169P3HIGHCVSS 7.7v3.2.0sev3.2.0sg+444 more2025-02-05
CVE-2025-20169 [HIGH] CWE-805 CVE-2025-20169: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20174P3HIGHCVSS 7.7v3.11.0sv3.11.1s+257 more2025-02-05
CVE-2025-20174 [HIGH] CWE-805 CVE-2025-20174: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20176P3HIGHCVSS 7.7v3.3.0sev3.3.1se+378 more2025-02-05
CVE-2025-20176 [HIGH] CWE-248 CVE-2025-20176: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20173P3HIGHCVSS 7.7v3.2.0sev3.2.0sg+448 more2025-02-05
CVE-2025-20173 [HIGH] CWE-248 CVE-2025-20173: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd
CVE-2025-20175P3HIGHCVSS 7.7v3.2.0sev3.2.0sg+452 more2025-02-05
CVE-2025-20175 [HIGH] CWE-805 CVE-2025-20175: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
nvd