Vulnerabilities > Cisco > IOS XE

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-12664 Improper Authentication vulnerability in Cisco IOS XE 16.6.4
A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Integrated Services Routers (ISRs) could allow an unauthenticated, adjacent attacker to pass IPv4 traffic through an ISDN channel prior to successful PPP authentication.
network
low complexity
cisco CWE-287
7.5
2019-09-25 CVE-2019-12663 Improper Input Validation vulnerability in Cisco IOS XE 16.12.1/16.6.4
A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
8.6
2019-09-25 CVE-2019-12662 Improper Verification of Cryptographic Signature vulnerability in Cisco products
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device.
local
low complexity
cisco CWE-347
6.7
2019-09-25 CVE-2019-12661 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root.
local
low complexity
cisco CWE-78
6.7
2019-09-25 CVE-2019-12660 Exposure of Resource to Wrong Sphere vulnerability in Cisco IOS XE
A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the underlying memory of an affected device.
local
low complexity
cisco CWE-668
5.5
2019-09-25 CVE-2019-12659 Resource Exhaustion vulnerability in Cisco IOS XE 16.10.1
A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the HTTP server to crash.
network
low complexity
cisco CWE-400
7.5
2019-09-25 CVE-2019-12658 Unspecified vulnerability in Cisco IOS XE 16.6.1/16.8.1
A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to exhaust filesystem resources on an affected device and cause a denial of service (DoS) condition.
network
low complexity
cisco
7.5
2019-09-25 CVE-2019-12657 Improper Input Validation vulnerability in Cisco IOS XE 16.3.6
A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-20
7.5
2019-09-25 CVE-2019-12654 NULL Pointer Dereference vulnerability in Cisco IOS XE 15.6(1)S4.2/16.3.8/16.9.1
A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-476
7.5
2019-09-25 CVE-2019-12653 Improper Input Validation vulnerability in Cisco IOS XE 16.10.1/16.9
A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-20
7.5