cbcvebase.

Cisco IOS XR vulnerabilities

174 known vulnerabilities affecting cisco/ios_xr.

Total CVEs
174
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH91MEDIUM77LOW3

Vulnerabilities

Page 6 of 9
CVE-2011-0943P4HIGHCVSS 7.8v3.8.3v3.8.4+1 more2011-05-31
CVE-2011-0943 [HIGH] CWE-399 CVE-2011-0943: Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO pro Cisco IOS XR 3.8.3, 3.8.4, and 3.9.1 allows remote attackers to cause a denial of service (NetIO process restart or device reload) via a crafted IPv4 packet, aka Bug ID CSCth44147.
nvd
CVE-2024-20456P4MEDIUMCVSS 6.7v24.2.12024-07-10
CVE-2024-20456 [MEDIUM] CWE-732 CVE-2024-20456: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfully, the attacker must have root-system privileges on the affected device. This vulnerability is due
nvd
CVE-2025-20177P4MEDIUMCVSS 6.7fixed in 7.11.21≥ 24.2, < 24.2.2+2 more2025-03-12
CVE-2025-20177 [MEDIUM] CWE-274 CVE-2025-20177: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR image signature verification and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device. This vulnerability is due to incomplete
nvd
CVE-2025-20143P4MEDIUMCVSS 6.7fixed in 7.9.12025-03-12
CVE-2025-20143 [MEDIUM] CWE-347 CVE-2025-20143: A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local att A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Secure Boot functionality and load unverified software on an affected device. To exploit this vulnerability, the attacker must have root-system privileges on the affected device. This vulnerability is due to i
nvd
CVE-2011-0949P4HIGHCVSS 7.8v3.6.0v3.6.1+6 more2011-05-31
CVE-2011-0949 [HIGH] CWE-399 CVE-2011-0949: Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock fi Cisco IOS XR 3.6.x, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 does not properly remove sshd_lock files from /tmp/, which allows remote attackers to cause a denial of service (disk consumption) by making many SSHv1 connections, aka Bug ID CSCtd64417.
nvd
CVE-2019-1649P4MEDIUMCVSS 6.7v7.0.1v7.1.12019-05-13
CVE-2019-1649 [MEDIUM] CWE-284 CVE-2019-1649: A vulnerability in the logic that handles access control to one of the hardware components in Cisco' A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vuln
nvd
CVE-2021-34708P4MEDIUMCVSS 6.7fixed in 7.3.2≥ 7.4.0, < 7.4.12021-09-09
CVE-2021-34708 [MEDIUM] CWE-347 CVE-2021-34708: Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more informat
nvd
CVE-2015-0618P4HIGHCVSS 7.1v5.0.1v5.2.12015-02-21
CVE-2015-0618 [HIGH] CWE-19 CVE-2015-0618: Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Carrier Routing System X (CRS-X) devices allows remote attackers to cause a denial of service (line-card reload) via malformed IPv6 packets with extension headers, aka Bug ID CSCuq95241.
nvd
CVE-2023-20190P4MEDIUMCVSS 5.3fixed in 7.3.5≥ 7.5, < 7.5.4+2 more2023-09-13
CVE-2023-20190 [MEDIUM] CWE-264 CVE-2023-20190: A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Softwar A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to incorrect destination address range encoding in the compression module of an ACL that is
nvd
CVE-2021-1244P4MEDIUMCVSS 6.7fixed in 7.0.12≥ 7.1.0, < 7.2.1+1 more2021-02-04
CVE-2021-1244 [MEDIUM] CWE-347 CVE-2021-1244: Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when run Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these
nvd
CVE-2021-1136P4MEDIUMCVSS 6.7fixed in 7.0.12≥ 7.1.0, < 7.2.1+1 more2021-02-04
CVE-2021-1136 [MEDIUM] CWE-347 CVE-2021-1136: Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when run Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device. For more information about these
nvd
CVE-2018-0286P4MEDIUMCVSS 5.3v6.3.1v6.3.2+1 more2018-05-02
CVE-2018-0286 [MEDIUM] CWE-399 CVE-2018-0286: A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, re A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on affected system. The vulnerability is due to improper handling of malformed requests processed by the netconf process. An attacker could exploit this vulnerability by sending malicious reques
nvd
CVE-2017-12355P4MEDIUMCVSS 5.3v6.4.1_base2017-11-30
CVE-2017-12355 [MEDIUM] CWE-399 CVE-2017-12355: A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause one of the LPTS processes on an affected system to restart unexpectedly, resulting in a brief denial of service (DoS) condition. The vulnerability is due to incomplete
nvd
CVE-2021-34709P4MEDIUMCVSS 6.4fixed in 7.3.2≥ 7.4.0, < 7.4.12021-09-09
CVE-2021-34709 [MEDIUM] CWE-347 CVE-2021-34709: Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. For more informat
nvd
CVE-2015-0694P4MEDIUMCVSS 5.0v5.3.0_base2015-04-11
CVE-2015-0694 [MEDIUM] CWE-284 CVE-2015-0694: Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a sin Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
nvd
CVE-2013-5549P4HIGHCVSS 7.1v3.8.1v3.8.2+14 more2013-10-25
CVE-2013-5549 [HIGH] CVE-2013-5549: Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of service (transmission outage) via (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCuh30380.
nvd
CVE-2020-3120P4MEDIUMCVSS 6.5v5.2.5v6.4.2+3 more2020-02-05
CVE-2020-3120 [MEDIUM] CWE-190 CVE-2020-3120: A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to a missing check when the affected software proce
nvd
CVE-2009-0629P4MEDIUMCVSS 5.4v12.42009-03-27
CVE-2009-0629 [MEDIUM] CVE-2009-0629: The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel C The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over T
nvd
CVE-2023-20233P4MEDIUMCVSS 6.5fixed in 7.5.4≥ 7.6, < 7.6.3+3 more2023-09-13
CVE-2023-20233 [MEDIUM] CWE-476 CVE-2023-20233: A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could al A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs). An attacker could exploit this vulnerability by
nvd
CVE-2019-1909P4MEDIUMCVSS 5.9≥ 4.3.1, < 6.6.22019-07-06
CVE-2019-1909 [MEDIUM] CWE-20 CVE-2019-1909: A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR A vulnerability in the implementation of Border Gateway Protocol (BGP) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to incorrect processing of certain BGP update messages. An attacker could exploit this vulnerability by
nvd
Cisco IOS XR vulnerabilities | cvebase