Vulnerabilities > Cisco > IOS XE > 16.12.1s

DATE CVE VULNERABILITY TITLE RISK
2020-06-03 CVE-2020-3213 Unspecified vulnerability in Cisco IOS XE
A vulnerability in the ROMMON of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to those of the root user of the underlying operating system.
local
low complexity
cisco
6.7
2020-06-03 CVE-2020-3211 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
7.2
2020-06-03 CVE-2020-3207 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot.
local
low complexity
cisco CWE-78
6.7
2020-06-03 CVE-2020-3204 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges.
local
low complexity
cisco CWE-20
6.7
2020-06-03 CVE-2020-3203 Memory Leak vulnerability in Cisco IOS XE
A vulnerability in the locally significant certificate (LSC) provisioning feature of Cisco Catalyst 9800 Series Wireless Controllers that are running Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak that could lead to a denial of service (DoS) condition.
network
low complexity
cisco CWE-401
8.6
2020-06-03 CVE-2020-3201 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system.
local
low complexity
cisco CWE-20
6.0
2020-04-29 CVE-2019-16011 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-20
7.8
2019-09-25 CVE-2019-12660 Exposure of Resource to Wrong Sphere vulnerability in Cisco IOS XE
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device.
local
low complexity
cisco CWE-668
5.5