Skip to main content

Vendor/product archive

cisco / ios_xe CVEs

Beta · best-effort

534 CVEs tagged to cisco / ios_xe16 Critical, 315 High, 202 Medium, 1 Low, 0 Unrated.

CVE-2018-0480

Published Oct 5, 2018

A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0477

Published Oct 5, 2018

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device wit…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0476

Published Oct 5, 2018

A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated,…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0475

Published Oct 5, 2018

A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0472

Published Oct 5, 2018

A vulnerability in the IPsec driver code of multiple Cisco IOS XE Software platforms and the Cisco ASA 5500-X Series Adaptive Security Appliance (ASA) could allow an unauthenticat…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0471

Published Oct 5, 2018

A vulnerability in the Cisco Discovery Protocol (CDP) module of Cisco IOS XE Software Releases 16.6.1 and 16.6.2 could allow an unauthenticated, adjacent attacker to cause a memor…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0470

Published Oct 5, 2018

A vulnerability in the web framework of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a buffer overflow condition on an affected device, resulting…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0469

Published Oct 5, 2018

A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0467

Published Oct 5, 2018

A vulnerability in the IPv6 processing code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is du…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0466

Published Oct 5, 2018

A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to cause an af…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0197

Published Oct 5, 2018

A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to corrupt the inte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0131

Published Aug 14, 2018

A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypt…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-0315

Published Jun 7, 2018

A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute ar…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-0257

Published Apr 19, 2018

A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an af…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0194

Published Apr 2, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0196

Published Mar 28, 2018

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to write arbitrary files to the operating system of…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0195

Published Mar 28, 2018

A vulnerability in the Cisco IOS XE Software REST API could allow an authenticated, remote attacker to bypass API authorization checks and use the API to perform privileged action…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0193

Published Mar 28, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0190

Published Mar 28, 2018

Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0189

Published Mar 28, 2018

A vulnerability in the Forwarding Information Base (FIB) code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, network attacker to cause a denial of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0188

Published Mar 28, 2018

Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0186

Published Mar 28, 2018

Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0185

Published Mar 28, 2018

Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0184

Published Mar 28, 2018

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and exec…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0183

Published Mar 28, 2018

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and exec…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 534 CVEsPage 13 of 22