Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 8 of 26
CVE-2022-20681P3HIGHCVSS 7.8v16.11.1v16.11.1a+65 more2022-04-15
CVE-2022-20681 [HIGH] CWE-266 CVE-2022-20681: A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisc
A vulnerability in the CLI of Cisco IOS XE Software for Cisco Catalyst 9000 Family Switches and Cisco Catalyst 9000 Family Wireless Controllers could allow an authenticated, local attacker to elevate privileges to level 15 on an affected device. This vulnerability is due to insufficient validation of user privileges after the user executes certain CLI
nvd
CVE-2023-20065P3HIGHCVSS 7.8v17.6.3v17.11.12023-03-23
CVE-2023-20065 [HIGH] CWE-284 CVE-2023-20065: A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow
A vulnerability in the Cisco IOx application hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to insufficient restrictions on the hosted application. An attacker could exploit this vulnerability by logging in to and then escaping the Ci
nvd
CVE-2018-0177P3HIGHCVSS 7.5vdenali-16.3.1vdenali-16.3.32018-03-28
CVE-2018-0177 [HIGH] CWE-19 CVE-2018-0177: A vulnerability in the IP Version 4 (IPv4) processing code of Cisco IOS XE Software running on Cisco
A vulnerability in the IP Version 4 (IPv4) processing code of Cisco IOS XE Software running on Cisco Catalyst 3850 and Cisco Catalyst 3650 Series Switches could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability
nvd
CVE-2022-20697P3HIGHCVSS 8.6v3.11.3aev3.11.3e+1 more2022-04-15
CVE-2022-20697 [HIGH] CWE-691 CVE-2022-20697: A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could
A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP reques
nvd
CVE-2012-0384P3HIGHCVSS 7.2v2.1v2.1.0+34 more2012-03-29
CVE-2012-0384 [HIGH] CWE-269 CVE-2012-0384: Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2)
nvd
CVE-2019-1950P3HIGHCVSS 8.4≤ 16.112020-02-19
CVE-2019-1950 [HIGH] CWE-255 CVE-2019-1950: A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to ga
A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, local attacker to gain unauthorized access to an affected device. The vulnerability is due to the existence of default credentials within the default configuration of an affected device. An attacker who has access to an affected device could log in with elevated privileges.
nvd
CVE-2017-3859P3HIGHCVSS 7.5v3.13.4sv3.13.5as+31 more2017-03-22
CVE-2017-3859 [HIGH] CWE-134 CVE-2017-3859: A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Agg
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a format string vulnerability when processing a crafted DHCP packet for Zero Touch Provisioning. An attacker could
nvd
CVE-2018-15372P3HIGHCVSS 8.1v16.8.1v16.9.12018-10-05
CVE-2018-15372 [HIGH] CWE-284 CVE-2018-15372: A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport
A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic through a Layer 3 interface of an affected device. The vulnerability is due to a logic error in
nvd
CVE-2020-3230P3HIGHCVSS 7.5v3.3.0sgv3.3.0xo+262 more2020-06-03
CVE-2020-3230 [HIGH] CWE-20 CVE-2020-3230: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent IKEv2 from establishing new security associations. The vulnerability is due to incorrect handling of crafted IKEv2 SA-Init packets. An attacker could exploit this vulnerabi
nvd
CVE-2018-0176P3HIGHCVSS 7.8v15.0\(5.59\)emdv16.1\(0\)+1 more2018-03-28
CVE-2018-0176 [HIGH] CWE-264 CVE-2018-0176: Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, lo
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device. The vulnerabilities are due to the affected software improperly sanitizing command arguments to prevent acce
nvd
CVE-2020-3393P3HIGHCVSS 7.8v16.12.12020-09-24
CVE-2020-3393 [HIGH] CWE-269 CVE-2020-3393: A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authent
A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. The attacker could execute IOS XE commands outside the application-hosting subsystem Docker container as well as on the underlying Linux operating system. These commands could be
nvd
CVE-2021-1529P3HIGHCVSS 7.8≥ 16.12, ≤ 17.0≥ 17.2, < 17.2.3+4 more2021-10-21
CVE-2021-1529 [HIGH] CWE-78 CVE-2021-1529: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability by authenticating to an affected device and submitting crafted input to the sy
nvd
CVE-2024-20307P3HIGHCVSS 7.5v3.4.8sgv3.7.4e+216 more2024-03-27
CVE-2024-20307 [HIGH] CWE-121 CVE-2024-20307: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabili
nvd
CVE-2024-20433P3HIGHCVSS 7.5v3.3.0sgv3.3.1sg+395 more2024-09-25
CVE-2024-20433 [HIGH] CWE-121 CVE-2024-20433: A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An
nvd
CVE-2021-1385P3MEDIUMCVSS 6.5v16.11.1v16.11.1a+45 more2021-03-24
CVE-2021-1385 [MEDIUM] CWE-22 CVE-2021-1385: A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could a
A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying operating system or host system. This vulnerability occurs because the device does not properly validate URIs in IOx API requests. An
nvd
CVE-2020-3203P3HIGHCVSS 8.6v16.1.1v16.1.2+52 more2020-06-03
CVE-2020-3203 [HIGH] CWE-400 CVE-2020-3203: A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst
A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak that could lead to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certa
nvd
CVE-2015-6360P3HIGHCVSS 7.5v3.10s_3.10.0sv3.10s_3.10.1s+18 more2016-04-21
CVE-2015-6360 [HIGH] CWE-119 CVE-2015-6360: The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a d
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.
nvd
CVE-2018-0194P3HIGHCVSS 7.8fixed in 16.3.12018-04-02
CVE-2018-0194 [HIGH] CWE-78 CVE-2018-0194: Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, lo
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of an affected device and execute commands with root privileges on the device. The vulnerabilities
nvd
CVE-2018-0185P3HIGHCVSS 7.8fixed in 16.3.12018-03-28
CVE-2018-0185 [HIGH] CWE-78 CVE-2018-0185: Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, lo
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of an affected device and execute commands with root privileges on the device. The vulnerabilities
nvd
CVE-2018-0182P3HIGHCVSS 7.8fixed in 16.3.12018-03-28
CVE-2018-0182 [HIGH] CWE-78 CVE-2018-0182: Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, lo
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of an affected device and execute commands with root privileges on the device. The vulnerabilities
nvd