VYPR

iOS Xe

by Cisco Systems, Inc.

CVEs (553)

  • CVE-2021-1436MedMar 24, 2021
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerability is due to insufficient validation of user-supplied input.…

  • CVE-2021-1434MedMar 24, 2021
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying file system. This vulnerability is due to insufficient validation of the parameters of a specific CLI command. An attacker could…

  • CVE-2019-1762MedMar 28, 2019
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed at encryption time, when…

  • CVE-2017-6795MedSep 7, 2017
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is…

  • CVE-2025-20214MedMay 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the Network Configuration Access Control Module (NACM) of Cisco IOS XE Software could allow an authenticated, remote attacker to obtain unauthorized read access to configuration or operational data. This vulnerability exists because a subtle change in inner…

  • CVE-2025-20195MedMay 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a CSRF attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the…

  • CVE-2024-20434MedSep 25, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device. This vulnerability is due to improper handling of frames with VLAN tag information. An attacker…

  • CVE-2021-1356MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These…

  • CVE-2021-1220MedMar 24, 2021
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition. These…

  • CVE-2020-3516MedSep 24, 2020
    risk 0.28cvss 4.3epss 0.02

    A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device. The vulnerability is due to insufficient input validation during authentication. An attacker could exploit this…

  • CVE-2020-3474MedSep 24, 2020
    risk 0.28cvss 4.3epss 0.01

    Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, resulting in a…

  • CVE-2020-3222MedJun 3, 2020
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an affected device. The vulnerability is due to the presence of a proxy service at a specific endpoint of…

  • CVE-2019-1761MedMar 28, 2019
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficient memory…

  • CVE-2018-0257MedApr 19, 2018
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the…

  • CVE-2017-12213MedSep 7, 2017
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open. This could allow the…

  • CVE-2017-6770MedAug 7, 2017
    risk 0.27cvss 4.2epss 0.02

    Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA)…

  • CVE-2016-6450LowNov 19, 2016
    risk 0.16cvss 2.5epss 0.00

    A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticated, local attacker to gain write access to some files in the underlying operating system. This vulnerability affects the following products if they are running a vulnerable release…

  • CVE-2015-6429Dec 19, 2015
    risk 0.00cvss epss 0.02

    The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.

  • CVE-2015-6383Dec 3, 2015
    risk 0.00cvss epss 0.00

    Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain certain root privileges by using the CLI to enter crafted filenames, aka Bug ID CSCuv93130.

  • CVE-2015-6280Sep 28, 2015
    risk 0.00cvss epss 0.04

    The SSHv2 functionality in Cisco IOS 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.6E before 3.6.3E, 3.7E before 3.7.1E, 3.10S before 3.10.6S, 3.11S before 3.11.4S, 3.12S before 3.12.3S, 3.13S before 3.13.3S, and 3.14S before 3.14.1S does not properly implement RSA authentication,…

Page 22 of 28