cbcvebase.

Cisco IOS XR vulnerabilities

174 known vulnerabilities affecting cisco/ios_xr.

Total CVEs
174
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH91MEDIUM77LOW3

Vulnerabilities

Page 5 of 9
CVE-2023-20135P3HIGHCVSS 7.0≥ 7.5.2, < 7.6≥ 7.7, < 7.10.12023-09-13
CVE-2023-20135 [HIGH] CWE-347 CVE-2023-20135: A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, loc A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses a
nvd
CVE-2016-1407P3HIGHCVSS 7.5v2.0.0v3.0.0+77 more2016-05-25
CVE-2016-1407 [HIGH] CWE-20 CVE-2016-1407: Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, whic Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.
nvd
CVE-2017-6719P3MEDIUMCVSS 6.7v6.0.2v6.0.2.012017-07-04
CVE-2017-6719 [MEDIUM] CWE-20 CVE-2017-6719: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.1.28i.BASE 6.2.1.22i.BASE 6.1.32.8i.BASE 6.1.31.3i.BASE 6.1.3
nvd
CVE-2019-12709P3MEDIUMCVSS 6.7≥ 5.1.0, < 6.5.3≥ 6.6.0, < 6.6.22019-09-25
CVE-2019-12709 [MEDIUM] CWE-78 CVE-2019-12709: A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Softwa A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with root privileges. The vulnerability is due to insufficient validation of a
nvd
CVE-2021-34722P3MEDIUMCVSS 6.7≥ 7.1.1, < 7.3.2≥ 7.4.0, < 7.4.12021-09-09
CVE-2021-34722 [MEDIUM] CWE-78 CVE-2021-34722: Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local att Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34721P3MEDIUMCVSS 6.7fixed in 7.3.2≥ 7.4.0, ≤ 7.4.1+1 more2021-09-09
CVE-2021-34721 [MEDIUM] CWE-78 CVE-2021-34721: Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local att Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2010-0137P4HIGHCVSS 7.8v3.4.1v3.4.2+7 more2010-01-21
CVE-2010-0137 [HIGH] CVE-2010-0137: Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574.
nvd
CVE-2011-3295P4HIGHCVSS 7.8v3.8.0v3.8.1+12 more2012-05-02
CVE-2011-3295 [HIGH] CWE-20 CVE-2011-3295: The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing Sy The NETIO and IPV4_IO processes in Cisco IOS XR 3.8 through 4.1, as used in Cisco Carrier Routing System and other products, allow remote attackers to cause a denial of service (CPU consumption) via crafted network traffic, aka Bug ID CSCti59888.
nvd
CVE-2024-20322P3MEDIUMCVSS 5.8v7.10.2v7.112024-03-13
CVE-2024-20322 [MEDIUM] CWE-284 CVE-2024-20322: A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to improper assignment of lookup keys to internal interface contexts. An attacker could exploit this vulnerability
nvd
CVE-2013-5503P4HIGHCVSS 7.8v4.3.12013-10-02
CVE-2013-5503 [HIGH] CWE-399 CVE-2013-5503: The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports, aka Bug ID CSCue69413.
nvd
CVE-2025-20144P3MEDIUMCVSS 5.8v6.5.1v6.5.2+41 more2025-03-12
CVE-2025-20144 [MEDIUM] CWE-284 CVE-2025-20144: A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR S A vulnerability in the hybrid access control list (ACL) processing of IPv4 packets in Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect handling of packets when a specific configuration of the hybrid ACL exists. An attacker could exploit this vulnerability by att
nvd
CVE-2011-1651P4HIGHCVSS 7.8v3.0v3.9.0+6 more2011-05-31
CVE-2011-1651 [HIGH] CWE-399 CVE-2011-1651: Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is Cisco IOS XR 3.9.x and 4.0.x before 4.0.3 and 4.1.x before 4.1.1, when an SPA interface processor is installed, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCto45095.
nvd
CVE-2018-0241P4HIGHCVSS 7.4v4.0.4.basev4.1.3.base+11 more2018-04-19
CVE-2018-0241 [HIGH] CWE-399 CVE-2018-0241: A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an una A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadcast packets that are forwarded to an IPv4 helper address. An attacker could exploit this vulner
nvd
CVE-2019-1846P4HIGHCVSS 7.4v5.3.32019-05-16
CVE-2019-1846 [HIGH] CWE-20 CVE-2019-1846: A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintena A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to the
nvd
CVE-2019-1918P4HIGHCVSS 7.4≥ 6.5.2, < 6.6.32019-08-07
CVE-2019-1918 [HIGH] CWE-20 CVE-2019-1918: A vulnerability in the implementation of Intermediate System&ndash;to&ndash;Intermediate System (IS& A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS-IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of IS–IS link-state protocol data units (PD
nvd
CVE-2018-15428P4MEDIUMCVSS 6.8v6.0.1v6.0.2+8 more2018-10-05
CVE-2018-15428 [MEDIUM] CWE-20 CVE-2018-15428: A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain BGP update messages. An attacker could exploit this vulnerability by sending BGP update
nvd
CVE-2019-1910P4HIGHCVSS 7.4fixed in 6.6.32019-08-07
CVE-2019-1910 [HIGH] CWE-20 CVE-2019-1910: A vulnerability in the implementation of the Intermediate System&ndash;to&ndash;Intermediate System A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of crafted IS–IS link-state protocol dat
nvd
CVE-2022-20758P4MEDIUMCVSS 6.8fixed in 6.8.2≥ 7.0, < 7.3.2+1 more2022-04-15
CVE-2022-20758 [MEDIUM] CWE-399 CVE-2022-20758: A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) funct A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the incorrect processing of a BGP update message that contains specific EVPN attributes. An at
nvd
CVE-2019-16027P4MEDIUMCVSS 6.5v4.3.2v5.2.5+15 more2020-01-26
CVE-2019-16027 [MEDIUM] CWE-20 CVE-2019-16027: A vulnerability in the implementation of the Intermediate System&ndash;to&ndash;Intermediate System A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the IS–IS process. The vulnerability is due to improper handling of a Simple Network Management Protocol (S
nvd
CVE-2025-20145P4MEDIUMCVSS 5.8v6.5.1v6.5.2+59 more2025-03-12
CVE-2025-20145 [MEDIUM] CWE-264 CVE-2025-20145: A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR A vulnerability in the access control list (ACL) processing in the egress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability exists because certain packets are handled incorrectly when they are received on an ingress interface on one line card and destined out of an egres
nvd
Cisco IOS XR vulnerabilities | cvebase