Vulnerabilities > Cisco > IOS XE > 16.12.4a

DATE CVE VULNERABILITY TITLE RISK
2021-03-24 CVE-2021-1220 Unspecified vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to cause the web UI software to become unresponsive and consume vty line instances, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
4.3
2021-03-24 CVE-2021-1453 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XE
A vulnerability in the software image verification functionality of Cisco IOS XE Software for the Cisco Catalyst 9000 Family of switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time.
low complexity
cisco CWE-347
6.8
2021-03-24 CVE-2021-1446 Improper Check for Unusual or Exceptional Conditions vulnerability in Cisco IOS XE
A vulnerability in the DNS application layer gateway (ALG) functionality used by Network Address Translation (NAT) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-754
7.5
2021-03-24 CVE-2021-1442 Information Exposure Through Log Files vulnerability in Cisco IOS XE
A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker to elevate privileges to the level of an Administrator user (level 15) on an affected device.
local
cisco CWE-532
6.9
2021-03-24 CVE-2021-1436 Path Traversal vulnerability in Cisco IOS XE
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system.
local
low complexity
cisco CWE-22
4.4
2021-03-24 CVE-2021-1432 Injection vulnerability in Cisco IOS XE and IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user.
local
low complexity
cisco CWE-74
7.3
2021-03-24 CVE-2021-1431 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the vDaemon process of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a device to reload, resulting a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5
2021-03-24 CVE-2021-1403 Improper Restriction of Rendered UI Layers or Frames vulnerability in Cisco IOS XE
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-1021
7.4
2021-03-24 CVE-2021-1398 Leftover Debug Code vulnerability in Cisco IOS XE
A vulnerability in the boot logic of Cisco IOS XE Software could allow an authenticated, local attacker with level 15 privileges or an unauthenticated attacker with physical access to execute arbitrary code on the underlying Linux operating system of an affected device.
low complexity
cisco CWE-489
6.8
2021-03-24 CVE-2021-1390 Write-what-where Condition vulnerability in Cisco IOS XE
A vulnerability in one of the diagnostic test CLI commands of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary code on an affected device.
local
low complexity
cisco CWE-123
6.7