Vulnerabilities > Cisco > IOS XE > 16.9.3h

DATE CVE VULNERABILITY TITLE RISK
2020-09-24 CVE-2020-3527 Resource Exhaustion vulnerability in Cisco IOS XE
A vulnerability in the Polaris kernel of Cisco Catalyst 9200 Series Switches could allow an unauthenticated, remote attacker to crash the device.
network
low complexity
cisco CWE-400
7.8
2020-09-24 CVE-2020-3516 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web server authentication of Cisco IOS XE Software could allow an authenticated, remote attacker to crash the web server on the device.
network
low complexity
cisco CWE-20
4.0
2020-09-24 CVE-2020-3425 Unspecified vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to elevate privileges to the level of an Administrator user on an affected device.
network
low complexity
cisco
8.8
2020-09-24 CVE-2020-3417 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot time and break the chain of trust.
local
low complexity
cisco CWE-78
6.7
2020-06-03 CVE-2020-3230 Improper Input Validation vulnerability in Cisco IOS
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent IKEv2 from establishing new security associations.
network
low complexity
cisco CWE-20
5.0
2020-06-03 CVE-2020-3229 Incorrect Authorization vulnerability in Cisco IOS XE
A vulnerability in Role Based Access Control (RBAC) functionality of Cisco IOS XE Web Management Software could allow a Read-Only authenticated, remote attacker to execute commands or configuration changes as an Admin user.
network
low complexity
cisco CWE-863
critical
9.0
2020-06-03 CVE-2020-3227 Incorrect Authorization vulnerability in Cisco IOS XE
A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization.
network
low complexity
cisco CWE-863
critical
9.8
2020-06-03 CVE-2020-3220 Insufficient Verification of Data Authenticity vulnerability in Cisco IOS XE
A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series Integrated Services Routers and Cisco Catalyst 9800-L Wireless Controllers could allow an unauthenticated, remote attacker to disconnect legitimate IPsec VPN sessions to an affected device.
network
cisco CWE-345
7.1
2020-06-03 CVE-2020-3219 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with administrative privileges on the underlying operating system of an affected device.
network
low complexity
cisco CWE-20
critical
9.0
2020-06-03 CVE-2020-3218 Improper Input Validation vulnerability in Cisco IOS XE
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code with root privileges on the underlying Linux shell.
network
low complexity
cisco CWE-20
critical
9.0