VYPR

IOS and IOS XE Software

by Cisco Systems, Inc.

CVEs (265)

  • CVE-2023-20066MedMar 23, 2023
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a directory traversal and access resources that are outside the filesystem mountpoint of the web UI. This vulnerability is due to an insufficient security…

  • CVE-2020-3487MedSep 24, 2020
    risk 0.42cvss 6.5epss 0.00

    Multiple vulnerabilities in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS)…

  • CVE-2026-20311MedAug 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the…

  • CVE-2026-20115MedMar 25, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this…

  • CVE-2026-20104MedMar 25, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an…

  • CVE-2025-20240MedSep 24, 2025
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied…

  • CVE-2022-20944MedOct 10, 2022
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerability is due to an improper check in the…

  • CVE-2021-1381MedMar 24, 2021
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with high privileges or an unauthenticated attacker with physical access to the device to open a debugging console. The vulnerability is due to insufficient command authorization restrictions.…

  • CVE-2020-3479MedSep 24, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service…

  • CVE-2025-20338MedSep 24, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation…

  • CVE-2025-20155MedMay 7, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient input validation of the bootstrap file that is read by the system software…

  • CVE-2024-20306MedMar 27, 2024
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacker must have level…

  • CVE-2020-3503MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to insufficient file system permissions on an affected device.…

  • CVE-2020-3476MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient validation of the parameters of a…

  • CVE-2020-3393MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. The attacker could execute IOS XE commands outside the application-hosting subsystem Docker container…

  • CVE-2020-3201MedJun 3, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system. The vulnerability is…

  • CVE-2025-20225MedAug 14, 2025
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger…

  • CVE-2024-20508MedSep 25, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured security policies or cause a denial of service (DoS) condition on an affected…

  • CVE-2024-20316MedMar 27, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access resources that should have been protected by a configured IPv4 access control list (ACL). This vulnerability is due to improper…

  • CVE-2021-34697MedSep 23, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is due to incorrect…

Page 11 of 14