Vulnerabilities > Cisco > IOS XE

DATE CVE VULNERABILITY TITLE RISK
2019-09-25 CVE-2019-12650 OS Command Injection vulnerability in Cisco IOS and IOS XE
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
network
low complexity
cisco CWE-78
8.8
2019-09-25 CVE-2019-12649 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS and IOS XE
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device.
local
low complexity
cisco CWE-347
6.7
2019-09-25 CVE-2019-12647 NULL Pointer Dereference vulnerability in Cisco IOS XE Fuji16.7.1/Fuji16.8.1
A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-476
7.5
2019-09-25 CVE-2019-12646 Improper Initialization vulnerability in Cisco IOS XE
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-665
7.5
2019-08-28 CVE-2019-12643 Improper Authentication vulnerability in Cisco IOS XE 15.5(3)S3.16/16.6.5
A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device.
network
low complexity
cisco CWE-287
critical
10.0
2019-08-21 CVE-2019-12624 Cross-Site Request Forgery (CSRF) vulnerability in Cisco IOS XE
A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device.
network
low complexity
cisco CWE-352
8.8
2019-06-21 CVE-2019-1904 Cross-Site Request Forgery (CSRF) vulnerability in Cisco IOS XE 16.1.3/16.2.1/16.3.1
A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.
network
low complexity
cisco CWE-352
8.8
2019-05-13 CVE-2019-1862 Improper Input Validation vulnerability in Cisco IOS XE 16.3.7
A vulnerability in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
network
low complexity
cisco CWE-20
7.2
2019-05-13 CVE-2019-1649 Improper Locking vulnerability in Cisco products
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component.
local
low complexity
cisco CWE-667
6.7
2019-03-28 CVE-2019-1762 Information Exposure vulnerability in Cisco IOS and IOS XE
A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device.
local
low complexity
cisco CWE-200
4.4