VYPR

Ios Xe Sd Wan

by Cisco Systems, Inc.

CVEs (26)

  • CVE-2021-34724MedSep 23, 2021
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must be authenticated on an affected device as a PRIV15 user.…

  • CVE-2021-1454MedMar 24, 2021
    risk 0.39cvss 6.0epss 0.00

    Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI commands. An attacker…

  • CVE-2021-1383MedMar 24, 2021
    risk 0.39cvss 6.0epss 0.01

    Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI commands. An attacker…

  • CVE-2022-20850MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This vulnerability is due to insufficient input validation. An…

  • CVE-2024-20373MedNov 15, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) IPv4 access control list (ACL) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform SNMP polling of an affected device, even if it…

  • CVE-2025-20151MedMay 7, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an affected device using SNMP, even if the device is configured to…

Page 2 of 2