Cisco IOS XR vulnerabilities
174 known vulnerabilities affecting cisco/ios_xr.
Total CVEs
174
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
11
Severity breakdown
CRITICAL3HIGH91MEDIUM77LOW3
Vulnerabilities
Page 9 of 9
CVE-2014-3343P4MEDIUMCVSS 4.3v5.1.02014-09-10
CVE-2014-3343 [MEDIUM] CWE-20 CVE-2014-3343: Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (DHCPv6 daemon crash) via a ma
Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (DHCPv6 daemon crash) via a malformed DHCPv6 packet, aka Bug ID CSCuo59052.
nvd
CVE-2005-2451P4LOWCVSS 2.1v3.0.1v3.1.02005-08-03
CVE-2005-2451 [LOW] CVE-2005-2451: Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a l
Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.
nvd
CVE-2023-20064P4MEDIUMCVSS 4.6fixed in 7.9.1fixed in 7.6.1+1 more2023-03-09
CVE-2023-20064 [MEDIUM] CWE-862 CVE-2023-20064: A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unau
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line. This vulnerability is due to the inclusion of unnecessary commands within the GRUB environment that allow sensitive
nvd
CVE-2017-6666P4MEDIUMCVSS 6.0v6.0.0v6.0.1+7 more2017-06-13
CVE-2017-6666 [MEDIUM] CVE-2017-6666: A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence S
A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) tunnels, resulting in a denial of service (DoS) condition. More Information: CSCvd16665. Known Affec
nvd
CVE-2006-1928P4MEDIUMCVSS 5.0v3.0.1v3.1.0+6 more2006-04-20
CVE-2006-1928 [MEDIUM] CVE-2006-1928: Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 r
Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 routers, allows remote attackers to cause a denial of service (Modular Services Cards (MSC) crash or "MPLS packet handling problems") via certain MPLS packets, as identified by Cisco bug IDs (1) CSCsd15970 and (2) CSCsd55531.
nvd
CVE-2006-1927P4MEDIUMCVSS 5.0v3.0.1v3.1.0+6 more2006-04-20
CVE-2006-1927 [MEDIUM] CVE-2006-1927: Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 o
Cisco IOS XR, when configured for Multi Protocol Label Switching (MPLS) and running on Cisco CRS-1 or Cisco 12000 series routers, allows remote attackers to cause a denial of service (Line card crash) via certain MPLS packets, as identified by Cisco bug ID CSCsc77475.
nvd
CVE-2014-3335P4MEDIUMCVSS 4.6≤ 4.3.2v4.3.0+1 more2014-08-26
CVE-2014-3335 [MEDIUM] CWE-20 CVE-2014-3335: Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of p
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.
nvd
CVE-2013-5565P4MEDIUMCVSS 4.3v5.1.02013-11-08
CVE-2013-5565 [MEDIUM] CWE-119 CVE-2013-5565: The OSPFv3 functionality in Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (p
The OSPFv3 functionality in Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (process crash) via a malformed LSA Type-1 packet, aka Bug ID CSCuj82176.
nvd
CVE-2020-3449P4MEDIUMCVSS 4.3fixed in 7.1.2≥ 7.2.0, < 7.2.1+1 more2020-08-17
CVE-2020-3449 [MEDIUM] CWE-754 CVE-2020-3449: A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Softwa
A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent authorized users from monitoring the BGP status and cause the BGP process to stop processing new updates, resulting in a denial of service (DOS) condition. The vulnerability is due to an inco
nvd
CVE-2015-4195P4MEDIUMCVSS 4.0v5.1.1.k9sec2015-06-19
CVE-2015-4195 [MEDIUM] CWE-399 CVE-2015-4195: Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error,
Cisco IOS XR 5.1.1.K9SEC allows remote authenticated users to cause a denial of service (vty error, and SSH and TELNET outage) via a crafted disconnect action within an SSH session, aka Bug ID CSCul63127.
nvd
CVE-2014-3377P4MEDIUMCVSS 4.0v2.0v3.0+53 more2014-09-20
CVE-2014-3377 [MEDIUM] CWE-20 CVE-2014-3377: snmpd in Cisco IOS XR 5.1 and earlier allows remote authenticated users to cause a denial of service
snmpd in Cisco IOS XR 5.1 and earlier allows remote authenticated users to cause a denial of service (process reload) via a malformed SNMPv2 packet, aka Bug ID CSCun67791.
nvd
CVE-2013-3464P4MEDIUMCVSS 4.6v2.0\(.0\)v3.0\(.0\)+55 more2013-08-13
CVE-2013-3464 [MEDIUM] CWE-119 CVE-2013-3464: Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corrup
Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corruption, improper mutex handling, and device reload) by starting an outbound flood of large ICMP Echo Request packets and stopping this with a CTRL-C sequence, aka Bug ID CSCui60347.
nvd
CVE-2009-1154P4LOWCVSS 3.3≤ 3.8.1v3.4+17 more2009-08-21
CVE-2009-1154 [LOW] CWE-119 CVE-2009-1154: Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash)
Cisco IOS XR 3.8.1 and earlier allows remote attackers to cause a denial of service (process crash) via a long BGP UPDATE message, as demonstrated by a message with many AS numbers in the AS Path Attribute.
nvd
CVE-2009-2056P4LOWCVSS 3.3≤ 3.8.1v3.0+30 more2009-08-21
CVE-2009-2056 [LOW] CWE-264 CVE-2009-2056: Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (proce
Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.
nvd
← Previous9 / 9