Cisco IOS XE vulnerabilities
505 known vulnerabilities affecting cisco/ios_xe.
Total CVEs
505
CISA KEV
27
actively exploited
Public exploits
8
Exploited in wild
33
Severity breakdown
CRITICAL20HIGH323MEDIUM161LOW1
Vulnerabilities
Page 9 of 26
CVE-2018-0193P3HIGHCVSS 7.8fixed in 16.3.12018-03-28
CVE-2018-0193 [HIGH] CWE-78 CVE-2018-0193: Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, lo
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of an affected device and execute commands with root privileges on the device. The vulnerabilities
nvd
CVE-2019-16011P3HIGHCVSS 7.8v16.10.2v16.11+4 more2020-04-29
CVE-2019-16011 [HIGH] CWE-77 CVE-2019-16011: A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attac
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by authenticating to the device and submitting crafted input to the CLI utili
nvd
CVE-2019-1748P3HIGHCVSS 7.4v3.3.0sev3.3.0xo+179 more2019-03-28
CVE-2019-1748 [HIGH] CWE-295 CVE-2019-1748: A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS X
A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplyi
nvd
CVE-2017-6664P3HIGHCVSS 7.5v3.10.8asv3.10.8s+27 more2017-08-07
CVE-2017-6664 [HIGH] CWE-295 CVE-2017-6664: A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthen
A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been revoked. This vulnerability affected devices that are running Release 16.x of Cisco IOS XE Softw
nvd
CVE-2024-20436P3HIGHCVSS 7.5v3.9.0asv3.9.1s+199 more2024-09-25
CVE-2024-20436 [HIGH] CWE-476 CVE-2024-20436: A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service featu
A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to a null pointer dereference when accessing specific URLs. An attacker could exploit this vulner
nvd
CVE-2024-20311P3HIGHCVSS 7.5v3.7.0bsv3.7.0s+316 more2024-03-27
CVE-2024-20311 [HIGH] CWE-674 CVE-2024-20311: A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to
nvd
CVE-2024-20308P3HIGHCVSS 7.5v3.3.0sgv3.3.1sg+379 more2024-03-27
CVE-2024-20308 [HIGH] CWE-787 CVE-2024-20308: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabil
nvd
CVE-2015-0644P3HIGHCVSS 7.8v3.8s.0v3.8s.1+13 more2015-03-26
CVE-2015-0644 [HIGH] CWE-20 CVE-2015-0644: AppNav in Cisco IOS XE 3.8 through 3.10 before 3.10.3S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.
AppNav in Cisco IOS XE 3.8 through 3.10 before 3.10.3S, 3.11 before 3.11.3S, 3.12 before 3.12.1S, 3.13 before 3.13.0S, 3.14 before 3.14.0S, and 3.15 before 3.15.0S allows remote attackers to execute arbitrary code or cause a denial of service (device reload) via a crafted TCP packet, aka Bug ID CSCuo53622.
nvd
CVE-2019-1741P3HIGHCVSS 7.5v3.2.0jav16.6.1+12 more2019-03-28
CVE-2019-1741 [HIGH] CWE-20 CVE-2019-1741: A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software coul
A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure after it has been fre
nvd
CVE-2018-0170P3HIGHCVSS 7.5v16.4.12018-03-28
CVE-2018-0170 [HIGH] CWE-416 CVE-2018-0170: A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an un
A vulnerability in the Cisco Umbrella Integration feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition, related to the OpenDNS software. The vulnerability is due to a logic error that exists when handling a malformed incoming packet, leading to access to an internal data structure
nvd
CVE-2017-3857P3HIGHCVSS 7.5≥ 3.1.0, ≤ 3.18.02017-03-22
CVE-2017-3857 [HIGH] CWE-399 CVE-2017-3857: A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 through 15.6) and Cisco IOS XE (3.1 through 3.18) could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient validation of L2TP packets. An attacker could exploit this vul
nvd
CVE-2019-1738P3HIGHCVSS 7.5v3.2.0jav3.16.0as+53 more2019-03-28
CVE-2019-1738 [HIGH] CWE-20 CVE-2019-1738: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit these vulnerabilities by sending crafted DNS packets throu
nvd
CVE-2019-1739P3HIGHCVSS 7.5v3.2.0jav3.16.0as+53 more2019-03-28
CVE-2019-1739 [HIGH] CWE-20 CVE-2019-1739: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through
nvd
CVE-2019-12653P3HIGHCVSS 7.5v16.9v16.10.12019-09-25
CVE-2019-12653 [HIGH] CWE-20 CVE-2019-12653: A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthen
A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper parsing of Raw Socket Transport payloads. An attacker could exploit this vulnerability by establish
nvd
CVE-2019-12646P3HIGHCVSS 7.5v15.4\(3\)sv15.5\(3\)s+11 more2019-09-25
CVE-2019-12646 [HIGH] CWE-399 CVE-2019-12646: A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Applicati
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper processing of transient SIP packets on which NAT is performed on an affected devi
nvd
CVE-2019-12658P3HIGHCVSS 7.5v16.6.1v16.8.12019-09-25
CVE-2019-12658 [HIGH] CWE-400 CVE-2019-12658: A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an u
A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesystem resources on an affected device and cause a denial of service (DoS) condition. The vulnerability is due to ineffective management of the underlying filesystem resources. An attacker could exploit thi
nvd
CVE-2020-3421P3HIGHCVSS 7.5v16.9.3v17.22020-09-24
CVE-2020-3421 [HIGH] CWE-754 CVE-2020-3421: Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an
Multiple vulnerabilities in the Zone-Based Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload or stop forwarding traffic through the firewall. The vulnerabilities are due to incomplete handling of Layer 4 packets through the device. An attacker could exploit these vulnerabilities by sen
nvd
CVE-2022-20719P3HIGHCVSS 7.2v16.3.1v16.3.1a+140 more2022-04-15
CVE-2022-20719 [HIGH] CWE-22 CVE-2022-20719: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) at
nvd
CVE-2022-20679P3HIGHCVSS 7.7v3.15.1xbsv3.15.2xbs+107 more2022-04-15
CVE-2022-20679 [HIGH] CWE-20 CVE-2022-20679: A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthentica
A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to buffer exhaustion that occurs while traffic on a configured IPsec tunnel is being processed. An attacker could expl
nvd
CVE-2021-1431P3HIGHCVSS 7.5v3.15.1xbsv3.15.2xbs+30 more2021-03-24
CVE-2021-1431 [HIGH] CWE-20 CVE-2021-1431: A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticate
A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition. This vulnerability is due to insufficient handling of malformed packets. An attacker could exploit this vulnerability by sending crafted traffic to an affected d
nvd