VYPR

IOS XE Software for Cisco Meraki

by Cisco Systems, Inc.

CVEs (272)

  • CVE-2020-3476MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the CLI implementation of a specific command of Cisco IOS XE Software could allow an authenticated, local attacker to overwrite arbitrary files in the underlying host file system. The vulnerability is due to insufficient validation of the parameters of a…

  • CVE-2020-3393MedSep 24, 2020
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the application-hosting subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to root on an affected device. The attacker could execute IOS XE commands outside the application-hosting subsystem Docker container…

  • CVE-2018-0476MedOct 5, 2018
    risk 0.39cvss 5.9epss 0.14

    A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to improper…

  • CVE-2024-20316MedMar 27, 2024
    risk 0.38cvss 5.8epss 0.00

    A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access resources that should have been protected by a configured IPv4 access control list (ACL). This vulnerability is due to improper…

  • CVE-2021-34697MedSep 23, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the Protection Against Distributed Denial of Service Attacks feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct denial of service (DoS) attacks to or through the affected device. This vulnerability is due to incorrect…

  • CVE-2021-34696MedSep 23, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the access control list (ACL) programming of Cisco ASR 900 and ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incorrect programming of hardware when an ACL is…

  • CVE-2021-1625MedSep 23, 2021
    risk 0.38cvss 5.8epss 0.01

    A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP responder-to-initiator…

  • CVE-2019-1757MedMar 28, 2019
    risk 0.38cvss 5.9epss 0.01

    A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation…

  • CVE-2024-20324MedMar 27, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords. This vulnerability is due to improper privilege checks. An attacker could exploit this vulnerability by…

  • CVE-2024-20309MedMar 27, 2024
    risk 0.36cvss 5.6epss 0.00

    A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload or stop responding. This vulnerability is due to the incorrect handling of specific ingress traffic when…

  • CVE-2022-20851MedSep 30, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by…

  • CVE-2021-1612MedSep 23, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file system. An attacker could exploit this…

  • CVE-2021-1443MedMar 24, 2021
    risk 0.36cvss 5.5epss 0.02

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerability exists because the affected software improperly…

  • CVE-2026-20114MedMar 25, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users. This vulnerability…

  • CVE-2025-20194MedMay 7, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker…

  • CVE-2021-1394MedMar 24, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the ingress traffic manager of Cisco IOS XE Software for Cisco Network Convergence System (NCS) 520 Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the web management interface of an affected device. This…

  • CVE-2019-1759MedMar 28, 2019
    risk 0.35cvss 5.3epss 0.04

    A vulnerability in access control list (ACL) functionality of the Gigabit Ethernet Management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the Gigabit Ethernet Management interface. The vulnerability…

  • CVE-2019-1742MedMar 28, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensitive configuration information. The vulnerability is due to improper access control to files within the web UI. An attacker could exploit this vulnerability by…

  • CVE-2026-20113MedMar 25, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to…

  • CVE-2025-20221MedMay 7, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This vulnerability is due to improper traffic filtering conditions on an affected device. An…