VYPR

IOS XE Software for Cisco Meraki

by Cisco Systems, Inc.

CVEs (272)

  • CVE-2023-20198CriKEVOct 16, 2023
    risk 0.88cvss 10.0epss 1.00

    Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two…

  • CVE-2023-20273HigKEVOct 25, 2023
    risk 0.69cvss 7.2epss 0.90

    A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending…

  • CVE-2025-20188CriMay 7, 2025
    risk 0.66cvss 10.0epss 0.27

    A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to…

  • CVE-2025-20352HigKEVSep 24, 2025
    risk 0.65cvss 7.7epss 0.39

    A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device…

  • CVE-2021-34770CriSep 23, 2021
    risk 0.65cvss 10.0epss 0.03

    A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative…

  • CVE-2019-12643CriAug 28, 2019
    risk 0.65cvss 10.0epss 0.05

    A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device. The vulnerability is due to an improper check performed by the area of code that…

  • CVE-2021-34727CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An…

  • CVE-2021-1619CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the…

  • CVE-2020-3227CriJun 3, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization. The vulnerability is due to incorrect…

  • CVE-2019-12624HigAug 21, 2019
    risk 0.62cvss 8.8epss 0.18

    A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The…

  • CVE-2025-20363CriSep 25, 2025
    risk 0.59cvss 9.0epss 0.08

    A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker…

  • CVE-2020-3229HigJun 3, 2020
    risk 0.58cvss 8.8epss 0.05

    A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user. The vulnerability is due to incorrect handling of RBAC…

  • CVE-2019-1753HigMar 28, 2019
    risk 0.58cvss 8.8epss 0.04

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated but unprivileged (level 1), remote attacker to run privileged Cisco IOS commands by using the web UI. The vulnerability is due to a failure to validate and sanitize input in Web Services…

  • CVE-2017-6741HigJul 17, 2017
    risk 0.58cvss 8.8epss 0.06

    A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device. …

  • CVE-2025-20186HigMay 7, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authenticated, remote attacker with a lobby ambassador user account to perform a command injection attack against an affected device. This…

  • CVE-2023-20231HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending…

  • CVE-2020-3425HigSep 24, 2020
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these…

  • CVE-2020-3400HigSep 24, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which they are not authorized.The vulnerability is due to insufficient authorization of web UI access requests. An attacker could…

  • CVE-2020-3141HigSep 24, 2020
    risk 0.57cvss 8.8epss 0.02

    Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device. For more information about these…

  • CVE-2020-3224HigJun 3, 2020
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to inject IOS commands to an affected device. The injected commands should require a higher privilege level in order to be…

Page 1 of 14