Cisco IOS XR vulnerabilities

171 known vulnerabilities affecting cisco/ios_xr.

Total CVEs
171
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
10
Severity breakdown
CRITICAL3HIGH88MEDIUM77LOW3

Vulnerabilities

Page 7 of 9
CVE-2016-1366MEDIUMCVSS 6.5v5.0.0v5.0.1+4 more2016-03-24
CVE-2016-1366 [MEDIUM] CWE-264 CVE-2016-1366: The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devi The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.
nvd
CVE-2016-1361MEDIUMCVSS 5.3v3.3.3v3.4.1+32 more2016-03-12
CVE-2016-1361 [MEDIUM] CWE-399 CVE-2016-1361: Cisco IOS XR through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices does not properly check for Cisco IOS XR through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices does not properly check for a Bidirectional Forwarding Detection (BFD) header in a UDP packet, which allows remote attackers to cause a denial of service (line-card restart) via a crafted packet, aka Bug ID CSCuw56900.
nvd
CVE-2015-6432HIGHCVSS 7.5v4.2.0v4.3.0+7 more2016-01-05
CVE-2015-6432 [HIGH] CWE-399 CVE-2015-6432: Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly res Cisco IOS XR 4.2.0, 4.3.0, 5.0.0, 5.1.0, 5.2.0, 5.2.2, 5.2.4, 5.3.0, and 5.3.2 does not properly restrict the number of Path Computation Elements (PCEs) for OSPF LSA opaque area updates, which allows remote attackers to cause a denial of service (device reload) via a crafted update, aka Bug ID CSCuw83486.
nvd
CVE-2015-6301MEDIUMCVSS 5.0v5.2.0_base2015-09-20
CVE-2015-6301 [MEDIUM] CWE-399 CVE-2015-6301: The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun72171.
nvd
CVE-2015-6297MEDIUMCVSS 5.0v5.2.0_base2015-09-18
CVE-2015-6297 [MEDIUM] CWE-399 CVE-2015-6297: The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers The DHCPv6 server in Cisco IOS on ASR 9000 devices with software 5.2.0 Base allows remote attackers to cause a denial of service (process reset) via crafted packets, aka Bug ID CSCun36525.
nvd
CVE-2015-4285MEDIUMCVSS 5.0v5.1.2v5.1.3+2 more2015-07-23
CVE-2015-4285 [MEDIUM] CWE-399 CVE-2015-4285: The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5 The Local Packet Transport Services (LPTS) implementation in Cisco IOS XR 5.1.2, 5.1.3, 5.2.1, and 5.2.2 on ASR9k devices makes incorrect decisions about the opening of TCP and UDP ports during the processing of flow base entries, which allows remote attackers to cause a denial of service (resource consumption) by sending traffic to these ports contin
nvd
CVE-2015-4284MEDIUMCVSS 5.0v5.3.02015-07-22
CVE-2015-4284 [MEDIUM] CWE-20 CVE-2015-4284: The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BGP process reload) via malformed BGPv4 packets, aka Bug ID CSCur70670.
nvd
CVE-2015-4223MEDIUMCVSS 5.0v5.1.32015-06-25
CVE-2015-4223 [MEDIUM] CWE-399 CVE-2015-4223: Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted Cisco IOS XR 5.1.3 allows remote attackers to cause a denial of service (process reload) via crafted MPLS Label Distribution Protocol (LDP) packets, aka Bug ID CSCuu77478.
nvd
CVE-2015-4205MEDIUMCVSS 5.7v5.3.12015-06-23
CVE-2015-4205 [MEDIUM] CWE-399 CVE-2015-4205: Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chi Cisco IOS XR 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (NPU chip reset or line-card reload) by sending crafted IEEE 802.3x flow-control PAUSE frames on the local network, aka Bug ID CSCut19959.
nvd
CVE-2015-4195MEDIUMCVSS 4.0v5.1.1.k9sec2015-06-19
CVE-2015-4195 [MEDIUM] CWE-399 CVE-2015-4195: Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.
nvd
CVE-2015-4191MEDIUMCVSS 5.0v5.2.12015-06-19
CVE-2015-4191 [MEDIUM] CWE-399 CVE-2015-4191: Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via Cisco IOS XR 5.2.1 allows remote attackers to cause a denial of service (ipv6_io service reload) via a malformed IPv6 packet, aka Bug ID CSCuq95565.
nvd
CVE-2015-0776MEDIUMCVSS 5.0v5.0.12015-06-12
CVE-2015-0776 [MEDIUM] CWE-399 CVE-2015-0776: telnetd in Cisco IOS XR 5.0.1 on Network Convergence System 6000 devices allows remote attackers to telnetd in Cisco IOS XR 5.0.1 on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (device reload) via a malformed TELNET packet, aka Bug ID CSCuq31566.
nvd
CVE-2015-0695HIGHCVSS 7.8v4.3.0v4.3.1+7 more2015-04-17
CVE-2015-0695 [HIGH] CWE-19 CVE-2015-0695: Cisco IOS XR 4.3.4 through 5.3.0 on ASR 9000 devices, when uRPF, PBR, QoS, or an ACL is configured, Cisco IOS XR 4.3.4 through 5.3.0 on ASR 9000 devices, when uRPF, PBR, QoS, or an ACL is configured, does not properly handle bridge-group virtual interface (BVI) traffic, which allows remote attackers to cause a denial of service (chip and card hangs and reloads) by triggering use of a BVI interface for IPv4 packets, aka Bug ID CSCur62957.
nvd
CVE-2015-0694MEDIUMCVSS 5.0v5.3.0_base2015-04-11
CVE-2015-0694 [MEDIUM] CWE-284 CVE-2015-0694: Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a sin Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attackers to bypass intended network-resource access restrictions by using an address that was not supposed to have been allowed, aka Bug ID CSCur28806.
nvd
CVE-2015-0672MEDIUMCVSS 5.0v5.2.22015-03-26
CVE-2015-0672 [MEDIUM] CWE-399 CVE-2015-0672: The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denia The DHCPv4 server in Cisco IOS XR 5.2.2 on ASR 9000 devices allows remote attackers to cause a denial of service (service outage) via a flood of crafted DHCP packets, aka Bug ID CSCup67822.
nvd
CVE-2015-0618HIGHCVSS 7.1v5.0.1v5.2.12015-02-21
CVE-2015-0618 [HIGH] CWE-19 CVE-2015-0618: Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Cisco IOS XR 5.0.1 and 5.2.1 on Network Convergence System (NCS) 6000 devices and 5.1.3 and 5.1.4 on Carrier Routing System X (CRS-X) devices allows remote attackers to cause a denial of service (line-card reload) via malformed IPv6 packets with extension headers, aka Bug ID CSCuq95241.
nvd
CVE-2014-8005MEDIUMCVSS 5.0≤ 5.1.02014-11-26
CVE-2014-8005 [MEDIUM] CWE-362 CVE-2014-8005: Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.
nvd
CVE-2014-3378MEDIUMCVSS 5.0v2.0v3.0+53 more2014-09-20
CVE-2014-3378 [MEDIUM] CWE-20 CVE-2014-3378: tacacsd in Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (proces tacacsd in Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed TACACS+ packet, aka Bug ID CSCum00468.
nvd
CVE-2014-3377MEDIUMCVSS 4.0v2.0v3.0+53 more2014-09-20
CVE-2014-3377 [MEDIUM] CWE-20 CVE-2014-3377: snmpd in Cisco IOS XR 5.1 and earlier allows remote authenticated users to cause a denial of service snmpd in Cisco IOS XR 5.1 and earlier allows remote authenticated users to cause a denial of service (process reload) via a malformed SNMPv2 packet, aka Bug ID CSCun67791.
nvd
CVE-2014-3376MEDIUMCVSS 5.0v2.0v3.0+53 more2014-09-20
CVE-2014-3376 [MEDIUM] CWE-20 CVE-2014-3376: Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) v Cisco IOS XR 5.1 and earlier allows remote attackers to cause a denial of service (process reload) via a malformed RSVP packet, aka Bug ID CSCuq12031.
nvd