Cisco IOS XR vulnerabilities
171 known vulnerabilities affecting cisco/ios_xr.
Total CVEs
171
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
10
Severity breakdown
CRITICAL3HIGH88MEDIUM77LOW3
Vulnerabilities
Page 1 of 9
CVE-2025-20363CRITICALCVSS 9.0v6.5.1v6.5.2+11 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
nvd
CVE-2025-20154HIGHCVSS 8.6v6.5.1v6.5.2+90 more2025-05-07
CVE-2025-20154 [HIGH] CWE-20 CVE-2025-20154: A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Softw
A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could cause the ipsla_ippm_server proces
nvd
CVE-2025-20146HIGHCVSS 8.6v7.9.21v7.10.2+9 more2025-03-12
CVE-2025-20146 [HIGH] CWE-20 CVE-2025-20146: A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series
A vulnerability in the Layer 3 multicast feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a denial of service (DoS) condition.
This v
nvd
CVE-2025-20209HIGHCVSS 7.5v6.5.1v6.5.2+38 more2025-03-12
CVE-2025-20209 [HIGH] CWE-770 CVE-2025-20209: A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software cou
A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an affected device from processing any control plane UDP packets.
This vulnerability is due to improper handling of malformed IKEv2 packets. An attacker could exploit this vulnerability by sending
nvd
CVE-2025-20142HIGHCVSS 8.6v6.7.2v6.7.3+32 more2025-03-12
CVE-2025-20142 [HIGH] CWE-20 CVE-2025-20142: A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy fe
A vulnerability in the IPv4 access control list (ACL) feature and quality of service (QoS) policy feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset,
nvd
CVE-2025-20115HIGHCVSS 8.6v6.5.1v6.5.2+91 more2025-03-12
CVE-2025-20115 [HIGH] CWE-120 CVE-2025-20115: A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomo
nvd
CVE-2025-20141HIGHCVSS 7.4v7.9.22025-03-12
CVE-2025-20141 [HIGH] CWE-770 CVE-2025-20141: A vulnerability in the handling of specific packets that are punted from a line card to a route proc
A vulnerability in the handling of specific packets that are punted from a line card to a route processor in Cisco IOS XR Software Release 7.9.2 could allow an unauthenticated, adjacent attacker to cause control plane traffic to stop working on multiple Cisco IOS XR platforms.
This vulnerability is due to incorrect handling of packets that are punted
nvd
CVE-2025-20138HIGHCVSS 8.8fixed in 24.2.21≥ 24.3, < 24.42025-03-12
CVE-2025-20138 [HIGH] CWE-78 CVE-2025-20138: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could
nvd
CVE-2025-20145MEDIUMCVSS 5.8v6.5.1v6.5.2+59 more2025-03-12
CVE-2025-20145 [MEDIUM] CWE-264 CVE-2025-20145: A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR
A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL.
This vulnerability exists because certain packets are handled incorrectly when they are received on an ingress interface on one line card and destined out of an egres
nvd
CVE-2025-20177MEDIUMCVSS 6.7fixed in 7.11.21≥ 24.2, < 24.2.2+2 more2025-03-12
CVE-2025-20177 [MEDIUM] CWE-274 CVE-2025-20177: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device.
This vulnerability is due to incomplete
nvd
CVE-2025-20144MEDIUMCVSS 5.8v6.5.1v6.5.2+41 more2025-03-12
CVE-2025-20144 [MEDIUM] CWE-284 CVE-2025-20144: A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR S
A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL.
This vulnerability is due to incorrect handling of packets when a specific configuration of the hybrid ACL exists. An attacker could exploit this vulnerability by att
nvd
CVE-2025-20143MEDIUMCVSS 6.7fixed in 7.9.12025-03-12
CVE-2025-20143 [MEDIUM] CWE-347 CVE-2025-20143: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device.
This vulnerability is due to i
nvd
CVE-2025-20172HIGHCVSS 7.7v7.0.1v7.0.2+46 more2025-02-05
CVE-2025-20172 [HIGH] CWE-248 CVE-2025-20172: A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR
A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted S
nvd
CVE-2021-1440MEDIUMCVSS 6.8≥ 4.3.0, < 7.3.12024-11-18
CVE-2021-1440 [MEDIUM] CWE-617 CVE-2021-1440: A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Ci
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting in a denial of service (DoS) condition.
This vulnerability is due to the incorrect handling of a specific RPKI to
nvd
CVE-2022-20849MEDIUMCVSS 6.1v6.5.1v6.5.2+31 more2024-11-15
CVE-2022-20849 [MEDIUM] CWE-391 CVE-2022-20849: A vulnerability in the Broadband Network Gateway PPP over Ethernet (PPPoE) feature of Cisco IOS
A vulnerability in the Broadband Network Gateway PPP over Ethernet (PPPoE) feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the PPPoE process to continually crash.
This vulnerability exists because the PPPoE feature does not properly handle an error condition within a specific crafted packet sequence. An at
nvd
CVE-2022-20846MEDIUMCVSS 4.3v6.5.1v6.5.2+58 more2024-11-15
CVE-2022-20846 [MEDIUM] CWE-120 CVE-2022-20846: A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software c
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload on an affected device.
This vulnerability is due to a heap buffer overflow in certain Cisco Discovery Protocol messages. An attacker could exploit this vuln
nvd
CVE-2024-20317HIGHCVSS 7.4v7.7.1v7.7.2+8 more2024-09-11
CVE-2024-20317 [HIGH] CWE-684 CVE-2024-20317: A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cis
A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dropped, resulting in a denial of service (DoS) condition.
This vulnerability is due to incorrect classification of
nvd
CVE-2024-20483HIGHCVSS 7.2v24.1.1v24.1.2+3 more2024-09-11
CVE-2024-20483 [HIGH] CWE-78 CVE-2024-20483: Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container o
Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the PON Manager MongoDB instance to perform command injection attacks on the P
nvd
CVE-2024-20398HIGHCVSS 7.8v6.5.1v6.5.2+74 more2024-09-11
CVE-2024-20398 [HIGH] CWE-78 CVE-2024-20398: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account coul
nvd
CVE-2024-20406HIGHCVSS 7.4≥ 6.8.1, < 7.0.0≥ 7.4.1, < 7.11.22024-09-11
CVE-2024-20406 [HIGH] CWE-20 CVE-2024-20406: A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (I
A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacke
nvd
1 / 9Next →