Vulnerabilities > Cisco > IOS XE > 16.1.4

DATE CVE VULNERABILITY TITLE RISK
2017-09-29 CVE-2017-12229 Improper Authentication vulnerability in Cisco IOS XE
A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software.
network
low complexity
cisco CWE-287
critical
9.8
2017-09-29 CVE-2017-12228 Improper Certificate Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate.
network
high complexity
cisco CWE-295
5.9
2017-09-29 CVE-2017-12222 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.5
2016-10-05 CVE-2016-6378 Resource Management Errors vulnerability in Cisco IOS XE
Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets that require NAT, aka Bug ID CSCuw85853.
network
low complexity
cisco CWE-399
7.5