Vulnerabilities > Cisco > IOS XE > 16.1.2

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-0182 OS Command Injection vulnerability in Cisco IOS XE
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of an affected device and execute commands with root privileges on the device.
local
low complexity
cisco CWE-78
7.8
2018-03-27 CVE-2017-12319 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.
network
high complexity
cisco
5.9
2017-10-19 CVE-2017-12272 Cross-site Scripting vulnerability in Cisco IOS XE 16.1.2/16.2.0/16.3(1)
A vulnerability in the web framework code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software.
network
low complexity
cisco CWE-79
6.1
2017-09-29 CVE-2017-12237 Unspecified vulnerability in Cisco IOS
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2017-09-29 CVE-2017-12229 Improper Authentication vulnerability in Cisco IOS XE
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software.
network
low complexity
cisco CWE-287
critical
9.8
2017-09-29 CVE-2017-12228 Improper Certificate Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate.
network
high complexity
cisco CWE-295
5.9
2017-09-29 CVE-2017-12222 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.5
2017-04-07 CVE-2017-6606 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user.
high complexity
cisco CWE-78
6.4
2016-11-19 CVE-2016-6450 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticated, local attacker to gain write access to some files in the underlying operating system.
local
high complexity
cisco CWE-20
2.5
2016-10-05 CVE-2016-6379 Improper Input Validation vulnerability in Cisco IOS and IOS XE
Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089.
network
low complexity
cisco CWE-20
7.5