cbcvebase.

Cisco IOS XR vulnerabilities

174 known vulnerabilities affecting cisco/ios_xr.

Total CVEs
174
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH91MEDIUM77LOW3

Vulnerabilities

Page 7 of 9
CVE-2020-3190P4MEDIUMCVSS 5.8fixed in 6.4.3≥ 6.6.0, < 6.6.3+2 more2020-03-04
CVE-2020-3190 [MEDIUM] CWE-400 CVE-2020-3190: A vulnerability in the IPsec packet processor of Cisco IOS XR Software could allow an unauthenticate A vulnerability in the IPsec packet processor of Cisco IOS XR Software could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition for IPsec sessions to an affected device. The vulnerability is due to improper handling of packets by the IPsec packet processor. An attacker could exploit this vulnerability by sending mali
nvd
CVE-2014-3353P4HIGHCVSS 7.1≤ 4.3.2v4.3.0+1 more2014-09-04
CVE-2014-3353 [HIGH] CWE-399 CVE-2014-3353: Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attac Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a denial of service (CPU consumption and IPv6 packet drops) via a malformed IPv6 packet, aka Bug ID CSCuo95165.
nvd
CVE-2019-15998P4MEDIUMCVSS 5.3v6.5.1v6.5.2+1 more2019-11-26
CVE-2019-15998 [MEDIUM] CWE-284 CVE-2019-15998: A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR S A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device. The vulnerability is due to a missing check in the NETCONF over SSH access control list (ACL). An attac
nvd
CVE-2024-20343P4MEDIUMCVSS 5.5v6.5.1v6.5.2+64 more2024-09-11
CVE-2024-20343 [MEDIUM] CWE-284 CVE-2024-20343: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system. The attacker must have valid credentials on the affected device. This vulnerability is due to incorrect validation of the arguments that are passed to a specific CLI command. A
nvd
CVE-2024-20390P4MEDIUMCVSS 5.3fixed in 24.1.22024-09-11
CVE-2024-20390 [MEDIUM] CWE-940 CVE-2024-20390: A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthent A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on XML TCP listen port 38751. This vulnerability is due to a lack of proper error validation of ingress XML packets. An attacker could exploit this vulnerability by sending a sustained, craft
nvd
CVE-2016-1366P4MEDIUMCVSS 6.5v5.0.0v5.0.1+4 more2016-03-24
CVE-2016-1366 [MEDIUM] CWE-264 CVE-2016-1366: The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devi The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.
nvd
CVE-2019-16018P4MEDIUMCVSS 6.5v6.6.1v6.6.2+2 more2020-01-26
CVE-2019-16018 [MEDIUM] CWE-399 CVE-2019-16018: A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functiona A vulnerability in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incorrect processing of a BGP update message that contains crafted EVPN attributes. An attacker cou
nvd
CVE-2017-6599P4MEDIUMCVSS 5.3v6.1.1v6.2.12017-04-07
CVE-2017-6599 [MEDIUM] CWE-772 CVE-2017-6599: A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software cou A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash due to a system memory leak, resulting in a denial of service (DoS) condition. This vulnerability affects Cisco IOS XR Software with gRPC enabled.
nvd
CVE-2014-2176P4HIGHCVSS 7.1v4.1.2v4.2.0+3 more2014-06-14
CVE-2014-2176 [HIGH] CWE-399 CVE-2014-2176: Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928.
nvd
CVE-2020-3364P4MEDIUMCVSS 5.3v6.7.1v7.0.2+4 more2020-06-18
CVE-2020-3364 [MEDIUM] CWE-284 CVE-2020-3364: A vulnerability in the access control list (ACL) functionality of the standby route processor manage A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the standby route processor management Gigabit Ethernet Management interface. The vulnerability is due to a logic error that
nvd
CVE-2024-20489P4MEDIUMCVSS 5.5v24.1.1v24.1.2+3 more2024-09-11
CVE-2024-20489 [MEDIUM] CWE-256 CVE-2024-20489: A vulnerability in the storage method of the PON Controller configuration file could allow an authen A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this v
nvd
CVE-2017-6718P4MEDIUMCVSS 6.7v6.0.2v6.0.2.012017-07-04
CVE-2017-6718 [MEDIUM] CWE-20 CVE-2017-6718: A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb99384. Known Affected Releases: 6.2.1.BASE. Known Fixed Releases: 6.2.11.3i.ROUT 6.2.1.29i.ROUT 6.2.1.26i.ROUT.
nvd
CVE-2016-1376P4MEDIUMCVSS 5.3v4.2.3v4.3.0+2 more2016-04-12
CVE-2016-1376 [MEDIUM] CWE-20 CVE-2016-1376: Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a d Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548.
nvd
CVE-2016-1433P4MEDIUMCVSS 5.3v6.0.0v6.0.1+1 more2016-09-18
CVE-2016-1433 [MEDIUM] CWE-399 CVE-2016-1433: Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packets, aka Bug ID CSCuz66289.
nvd
CVE-2008-1159P4HIGHCVSS 7.1v12.42008-05-22
CVE-2008-1159 [HIGH] CVE-2008-1159: Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to c Multiple unspecified vulnerabilities in the SSH server in Cisco IOS 12.4 allow remote attackers to cause a denial of service (device restart) via unknown vectors, aka Bug ID (1) CSCsk42419, (2) CSCsk60020, and (3) CSCsh51293.
nvd
CVE-2012-4617P4HIGHCVSS 7.1v4.1v4.1.1+4 more2012-09-27
CVE-2012-4617 [HIGH] CWE-20 CVE-2012-4617: The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2. The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
nvd
CVE-2019-1849P4MEDIUMCVSS 6.5≥ 6.1.0, < 6.3.3≥ 6.4.0, < 6.4.2+2 more2019-05-16
CVE-2019-1849 [MEDIUM] CWE-754 CVE-2019-1849: A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethern A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based Ethernet VPN (EVPN) implementation of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a logic error that occurs when the affected softwar
nvd
CVE-2015-6301P4MEDIUMCVSS 5.0v5.2.0_base2015-09-20
CVE-2015-6301 [MEDIUM] CWE-399 CVE-2015-6301: The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.
nvd
CVE-2015-6297P4MEDIUMCVSS 5.0v5.2.0_base2015-09-18
CVE-2015-6297 [MEDIUM] CWE-399 CVE-2015-6297: The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.
nvd
CVE-2015-0672P4MEDIUMCVSS 5.0v5.2.22015-03-26
CVE-2015-0672 [MEDIUM] CWE-399 CVE-2015-0672: The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denia The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.
nvd
Cisco IOS XR vulnerabilities | cvebase