cbcvebase.

Cisco IOS XR vulnerabilities

174 known vulnerabilities affecting cisco/ios_xr.

Total CVEs
174
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH91MEDIUM77LOW3

Vulnerabilities

Page 3 of 9
CVE-2024-20320P3HIGHCVSS 7.8v7.2.1v7.2.2+23 more2024-03-13
CVE-2024-20320 [HIGH] CWE-266 CVE-2024-20320: A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of arguments that are included with
nvd
CVE-2019-1712P3HIGHCVSS 7.5fixed in 6.2.3≥ 6.2.25, < 6.3.2+2 more2019-04-17
CVE-2019-1712 [HIGH] CWE-20 CVE-2019-1712: A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could a A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the PIM process to restart, resulting in a denial of service condition on an affected device. The vulnerability is due to the incorrect processing of crafted AutoRP packets. An attacker could exploit this v
nvd
CVE-2021-1370P3HIGHCVSS 7.8fixed in 7.0.12≥ 7.1.0, < 7.2.1+1 more2021-02-04
CVE-2021-1370 [HIGH] CWE-78 CVE-2021-1370: A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Netw A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running NCS540L software images could allow an authenticated, local attacker to elevate their privilege to root. To exploit this vulnerability, an attacker would need to have a valid account on an affected device.
nvd
CVE-2024-20304P3HIGHCVSS 7.5v7.7.1v7.7.2+16 more2024-09-11
CVE-2024-20304 [HIGH] CWE-401 CVE-2024-20304: A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software cou A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device. This vulnerability exists because the Mtrace2 code does not properly handle packet memory. An attacker could exploit this vulnerability by sending craf
nvd
CVE-2025-20209P3HIGHCVSS 7.5v6.5.1v6.5.2+38 more2025-03-12
CVE-2025-20209 [HIGH] CWE-770 CVE-2025-20209: A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software cou A vulnerability in the Internet Key Exchange version 2 (IKEv2) function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent an affected device from processing any control plane UDP packets. This vulnerability is due to improper handling of malformed IKEv2 packets. An attacker could exploit this vulnerability by sending
nvd
CVE-2021-1313P3HIGHCVSS 7.5≥ 5.0.0, < 5.2.6≥ 5.3.0, < 5.3.42021-02-04
CVE-2021-1313 [HIGH] CWE-399 CVE-2021-1313: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could al Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1288P3HIGHCVSS 7.5≥ 5.0.0, < 5.2.6≥ 5.3.0, < 5.3.4+1 more2021-02-04
CVE-2021-1288 [HIGH] CWE-399 CVE-2021-1288: Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could al Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2023-20236P3HIGHCVSS 7.8fixed in 7.10.12023-09-13
CVE-2023-20236 [HIGH] CWE-347 CVE-2023-20236: A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, loc A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification. An attacker could exploit this vulnerability by manipulating the boot parameters for image verification during the i
nvd
CVE-2020-3530P3HIGHCVSS 8.4fixed in 7.1.22020-09-04
CVE-2020-3530 [HIGH] CWE-264 CVE-2020-3530: A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could a A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required. The attacker must have valid credentials on the affected device. The vulnerability is due to incorrect mapping in the source code of t
nvd
CVE-2017-3876P3HIGHCVSS 7.5v6.1.0v6.1.12017-05-16
CVE-2017-3876 [HIGH] CWE-399 CVE-2017-3876: A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of gRPC requests. An attacker could exploit this vulnerability by repeatedly sending unauthenticated gRPC
nvd
CVE-2019-1711P3HIGHCVSS 7.5≥ 6.1.0, < 6.5.12019-04-17
CVE-2019-1711 [HIGH] CWE-20 CVE-2019-1711: A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow a A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of gRPC requests. An attacker could exploit this vulnerability by repeatedly sending unauthenticated gRPC r
nvd
CVE-2019-16021P3HIGHCVSS 7.5v6.6.1v6.6.2+2 more2020-09-23
CVE-2019-16021 [HIGH] CWE-399 CVE-2019-16021: Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attac
nvd
CVE-2021-34737P3HIGHCVSS 7.5fixed in 7.3.2≥ 7.4.0, ≤ 7.4.1+1 more2021-09-09
CVE-2021-34737 [HIGH] CWE-476 CVE-2021-34737: A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow a A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition. This vulnerability exists because certain DHCPv4 messages are improperly validated when they are processed by an affected devic
nvd
CVE-2019-16023P3HIGHCVSS 7.5v6.6.1v6.6.2+2 more2020-09-23
CVE-2019-16023 [HIGH] CWE-399 CVE-2019-16023: Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerabilities are due to incorrect processing of BGP update messages that contain crafted EVPN attributes. An attac
nvd
CVE-2023-20049P3HIGHCVSS 7.5fixed in 7.5.3≥ 7.6, < 7.6.2+1 more2023-03-09
CVE-2023-20049 [HIGH] CWE-805 CVE-2023-20049: A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IO A vulnerability in the bidirectional forwarding detection (BFD) hardware offload feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers, ASR 9902 Compact High-Performance Routers, and ASR 9903 Compact High-Performance Routers could allow an unauthenticated, remote attacker to cause a line card to reset, resulting in a
nvd
CVE-2016-9205P3HIGHCVSS 7.5v6.1.12016-12-14
CVE-2016-9205 [HIGH] CWE-399 CVE-2016-9205: A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauth A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. More Information: CSCvb14425. Known Affected Releases: 6.1.1.BASE. Known Fixed Releases: 6.1.2.6i.MGBL 6.1.22.9i.MGB
nvd
CVE-2020-3473P3HIGHCVSS 7.8≥ 5.0.0, < 7.0.12≥ 7.1.0, < 7.2.1+4 more2020-09-04
CVE-2020-3473 [HIGH] CWE-264 CVE-2020-3473: A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could a A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device. The vulnerability is due to incorrect mapping of a command to task groups within the source code. An attacker could exploit this vulnerab
nvd
CVE-2015-0695P3HIGHCVSS 7.8v4.3.0v4.3.1+7 more2015-04-17
CVE-2015-0695 [HIGH] CWE-19 CVE-2015-0695: Cisco IOS XR 4.3.4 through 5.3.0 on ASR 9000 devices, when uRPF, PBR, QoS, or an ACL is configured, Cisco IOS XR 4.3.4 through 5.3.0 on ASR 9000 devices, when uRPF, PBR, QoS, or an ACL is configured, does not properly handle bridge-group virtual interface (BVI) traffic, which allows remote attackers to cause a denial of service (chip and card hangs and reloads) by triggering use of a BVI interface for IPv4 packets, aka Bug ID CSCur62957.
nvd
CVE-2017-6731P3HIGHCVSS 7.5v4.3.2.mcastv6.0.2.base2017-07-10
CVE-2017-6731 [HIGH] CWE-119 CVE-2017-6731: A vulnerability in Multicast Source Discovery Protocol (MSDP) ingress packet processing for Cisco IO A vulnerability in Multicast Source Discovery Protocol (MSDP) ingress packet processing for Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the MSDP session to be unexpectedly reset, causing a short denial of service (DoS) condition. The MSDP session will restart within a few seconds. More Information: CSCvd94828. Known Af
nvd
CVE-2016-6428P3HIGHCVSS 7.8v6.1.12016-10-06
CVE-2016-6428 [HIGH] CWE-264 CVE-2016-6428: Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin p Cisco IOS XR 6.1.1 allows local users to execute arbitrary OS commands as root by leveraging admin privileges, aka Bug ID CSCva38349.
nvd
Cisco IOS XR vulnerabilities | cvebase