Cisco IOS XR vulnerabilities
174 known vulnerabilities affecting cisco/ios_xr.
Total CVEs
174
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH91MEDIUM77LOW3
Vulnerabilities
Page 1 of 9
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in 7.11.22023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2016-6415P1HIGHCVSS 7.5KEVPoC≥ 4.3.0, ≤ 4.3.4≥ 5.0.0, < 5.3.02016-09-19
CVE-2016-6415 [HIGH] CWE-200 CVE-2016-6415: The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.
nvd
CVE-2020-3118P1HIGHCVSS 8.8KEV≥ 6.6.0, < 6.6.12≥ 7.0.0, < 7.0.2+5 more2020-02-05
CVE-2020-3118 [HIGH] CWE-134 CVE-2020-3118: A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit t
nvd
CVE-2018-0167P1HIGHCVSS 8.8KEV≥ 4.1, < 5.1.32018-03-28
CVE-2018-0167 [HIGH] CWE-119 CVE-2018-0167: Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Ci
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCu
nvd
CVE-2020-3566P1HIGHCVSS 8.6KEVv6.4.22020-08-29
CVE-2020-3566 [HIGH] CWE-400 CVE-2020-3566: A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR So
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnera
nvd
CVE-2020-3569P1HIGHCVSS 8.6KEVv6.1.4v6.2.3+10 more2020-09-23
CVE-2020-3569 [HIGH] CWE-400 CVE-2020-3569: Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other p
nvd
CVE-2018-0175P1HIGHCVSS 8.0KEVv15.4\(3\)m4.12018-03-28
CVE-2018-0175 [HIGH] CWE-119 CVE-2018-0175: Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Softw
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Cisco Bug IDs: CSCvd73664.
nvd
CVE-2010-3035P2HIGHCVSS 7.5KEV≥ 3.4.0, ≤ 3.9.12010-08-30
CVE-2010-3035 [HIGH] CVE-2010-3035: Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transit
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.
nvd
CVE-2009-2055P2MEDIUMCVSS 5.9KEVv3.4v3.4.0+17 more2009-08-19
CVE-2009-2055 [MEDIUM] CWE-20 CVE-2009-2055: Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.
nvd
CVE-2025-20363P1CRITICALCVSS 9.0Exploitedv6.5.1v6.5.2+11 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
nvd
CVE-2016-1409P2HIGHCVSS 7.5Exploitedv2.0.0v3.0.0+78 more2016-05-29
CVE-2016-1409 [HIGH] CWE-20 CVE-2016-1409: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
nvd
CVE-2020-3284P2CRITICALCVSS 9.8fixed in 6.5.2fixed in 7.2.1+4 more2020-11-06
CVE-2020-3284 [CRITICAL] CWE-284 CVE-2020-3284: A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-
A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device. The PXE boot loader is part of the BIOS and runs over the management interface of hardware platforms that are runn
nvd
CVE-2019-1710P2CRITICALCVSS 9.8fixed in 6.5.3≥ 7.0, < 7.0.12019-04-17
CVE-2019-1710 [CRITICAL] CWE-20 CVE-2019-1710: A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services R
A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to access internal applications running on the sysadmin VM. The vulnerability is due to incorrect isolation of the secondary management interface from internal
nvd
CVE-2024-20381P2HIGHCVSS 8.8v6.5.1v6.5.2+86 more2024-09-11
CVE-2024-20381 [HIGH] CWE-285 CVE-2024-20381: A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) a
A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to modify the configuration of an affected application or device.
This
nvd
CVE-2026-20040P3HIGHCVSS 8.8fixed in 25.2.21≥ 25.3.1, < 25.4.22026-03-11
CVE-2026-20040 [HIGH] CWE-78 CVE-2026-20040: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could
nvd
CVE-2025-20138P3HIGHCVSS 8.8fixed in 24.2.21≥ 24.3, < 24.42025-03-12
CVE-2025-20138 [HIGH] CWE-78 CVE-2025-20138: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands. An attacker with a low-privileged account could
nvd
CVE-2019-1686P3HIGHCVSS 8.6≥ 5.1.1, < 6.5.2≥ 6.5.3, < 6.6.12019-04-17
CVE-2019-1686 [HIGH] CWE-284 CVE-2019-1686: A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 900
A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass protection offered by a configured ACL on an affected device. The vulnerability is due to incorrect processing of the ACL applied to an interface of an affecte
nvd
CVE-2021-34718P3HIGHCVSS 8.1fixed in 7.3.2≥ 7.4.0, < 7.4.12021-09-09
CVE-2021-34718 [HIGH] CWE-88 CVE-2021-34718: A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, rem
A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplied by the user for a specific file transfer method. An attacker with lower-level privileges cou
nvd
CVE-2007-4430P4MEDIUMCVSS 5.0PoCv2.0v3.0+4 more2007-08-20
CVE-2007-4430 [MEDIUM] CWE-20 CVE-2007-4430: Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
nvd
CVE-2019-1681P3HIGHCVSS 7.5fixed in 6.5.22019-02-21
CVE-2019-1681 [HIGH] CWE-200 CVE-2019-1681: A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could a
A vulnerability in the TFTP service of Cisco Network Convergence System 1000 Series software could allow an unauthenticated, remote attacker to retrieve arbitrary files from the targeted device, possibly resulting in information disclosure. The vulnerability is due to improper validation of user-supplied input within TFTP requests processed by the affec
nvd
1 / 9Next →