VYPR

iOS Xr Software

by Cisco Systems, Inc.

CVEs (277)

  • CVE-2018-0485HigOct 5, 2018
    risk 0.56cvss 8.6epss 0.04

    A vulnerability in the SM-1T3/E3 firmware on Cisco Second Generation Integrated Services Routers (ISR G2) and the Cisco 4451-X Integrated Services Router (ISR4451-X) could allow an unauthenticated, remote attacker to cause the ISR G2 Router or the SM-1T3/E3 module on the…

  • CVE-2018-0473HigOct 5, 2018
    risk 0.56cvss 8.6epss 0.03

    A vulnerability in the Precision Time Protocol (PTP) subsystem of Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition of the Precision Time Protocol. The vulnerability is due to insufficient processing of PTP packets.…

  • CVE-2018-0470HigOct 5, 2018
    risk 0.56cvss 8.6epss 0.04

    A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to the affected software…

  • CVE-2018-0467HigOct 5, 2018
    risk 0.56cvss 8.6epss 0.03

    A vulnerability in the IPv6 processing code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect handling of specific IPv6 hop-by-hop options. An attacker could exploit this…

  • CVE-2018-0164HigMar 28, 2018
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the Switch Integrated Security Features of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an interface queue wedge. The vulnerability is due to incorrect handling of crafted IPv6 packets. An attacker could exploit this…

  • CVE-2018-0157HigMar 28, 2018
    risk 0.56cvss 8.6epss 0.03

    A vulnerability in the Zone-Based Firewall code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a device to reload. The vulnerability is due to the way fragmented packets are handled in the firewall code. An attacker could exploit this…

  • CVE-2018-0132HigFeb 8, 2018
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause inconsistency between the routing information base (RIB) and the FIB, resulting in a denial of service (DoS) condition. The…

  • CVE-2018-0136HigJan 31, 2018
    risk 0.56cvss 8.6epss 0.03

    A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a denial of service…

  • CVE-2024-20489HigSep 11, 2024
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials. This vulnerability is due to improper storage of the unencrypted database credentials on the…

  • CVE-2023-20109MedKEVSep 27, 2023
    risk 0.55cvss 6.6epss 0.02

    A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an…

  • CVE-2022-20821MedKEVMay 26, 2022
    risk 0.55cvss 6.5epss 0.12

    A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon…

  • CVE-2020-3530HigSep 4, 2020
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required. The attacker must have valid credentials on the affected…

  • CVE-2025-20164HigMay 7, 2025
    risk 0.54cvss 8.3epss 0.00

    A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker…

  • CVE-2026-20277HigSep 2, 2026
    risk 0.53cvss 8.2epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered…

  • CVE-2025-20160HigSep 24, 2025
    risk 0.53cvss 8.1epss 0.00

    A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check…

  • CVE-2021-34718HigSep 9, 2021
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the SSH Server process of Cisco IOS XR Software could allow an authenticated, remote attacker to overwrite and read arbitrary files on the local device. This vulnerability is due to insufficient input validation of arguments that are supplied by the user for a…

  • CVE-2020-3257HigJun 3, 2020
    risk 0.53cvss 8.1epss 0.01

    Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker to cause a denial of…

  • CVE-2018-15372HigOct 5, 2018
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic through a Layer 3…

  • CVE-2018-0161MedKEVMar 28, 2018
    risk 0.53cvss 6.3epss 0.04

    A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of…

  • CVE-2023-20186HigSep 27, 2023
    risk 0.52cvss 8.0epss 0.01

    A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using…

Page 5 of 14