Vulnerabilities > Cisco > IOS XE > 16.1.1

DATE CVE VULNERABILITY TITLE RISK
2018-03-27 CVE-2017-12319 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.
network
high complexity
cisco
5.9
2017-09-29 CVE-2017-12237 Unspecified vulnerability in Cisco IOS
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2017-09-29 CVE-2017-12229 Improper Authentication vulnerability in Cisco IOS XE
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software.
network
low complexity
cisco CWE-287
critical
9.8
2017-09-29 CVE-2017-12228 Improper Certificate Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate.
network
high complexity
cisco CWE-295
5.9
2017-09-29 CVE-2017-12222 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.5
2017-04-07 CVE-2017-6606 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user.
high complexity
cisco CWE-78
6.4
2016-11-19 CVE-2016-6450 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticated, local attacker to gain write access to some files in the underlying operating system.
local
high complexity
cisco CWE-20
2.5
2016-10-05 CVE-2016-6379 Improper Input Validation vulnerability in Cisco IOS and IOS XE
Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089.
network
low complexity
cisco CWE-20
7.5
2016-10-05 CVE-2016-6382 Resource Management Errors vulnerability in Cisco IOS and IOS XE
Cisco IOS 15.2 through 15.6 and IOS XE 3.6 through 3.17 and 16.1 allow remote attackers to cause a denial of service (device restart) via a malformed IPv6 Protocol Independent Multicast (PIM) register packet, aka Bug ID CSCuy16399.
network
low complexity
cisco CWE-399
7.5
2016-05-29 CVE-2016-1409 Improper Input Validation vulnerability in Cisco products
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
network
low complexity
cisco CWE-20
7.5