Vulnerabilities > Cisco > IOS XE > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-20510 Incorrect Authorization vulnerability in Cisco IOS XE
A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass the pre-authentication access control list (ACL), which could allow access to network resources before user authentication. This vulnerability is due to a logic error when activating the pre-authentication ACL that is received from the authentication, authorization, and accounting (AAA) server.
low complexity
cisco CWE-863
critical
9.3
2023-10-16 CVE-2023-20198 Unspecified vulnerability in Cisco IOS XE
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
network
low complexity
cisco
critical
10.0
2023-09-27 CVE-2023-20186 Unspecified vulnerability in Cisco IOS
A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect processing of SCP commands in AAA command authorization checks.
network
low complexity
cisco
critical
9.1
2021-09-23 CVE-2021-1619 Use of Uninitialized Resource vulnerability in Cisco products
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory corruption that results in a denial of service (DoS) on an affected device This vulnerability is due to an uninitialized variable.
network
low complexity
cisco CWE-908
critical
9.1
2021-03-24 CVE-2021-1451 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XE
A vulnerability in the Easy Virtual Switching System (VSS) feature of Cisco IOS XE Software for Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying Linux operating system of an affected device.
network
low complexity
cisco CWE-119
critical
9.8
2020-06-03 CVE-2020-3227 Incorrect Authorization vulnerability in Cisco IOS XE
A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization.
network
low complexity
cisco CWE-863
critical
9.8
2019-08-28 CVE-2019-12643 Improper Authentication vulnerability in Cisco IOS XE 15.5(3)S3.16/16.6.5
A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on the managed Cisco IOS XE device.
network
low complexity
cisco CWE-287
critical
10.0
2018-06-07 CVE-2018-0315 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XE 16.7.1/16.8.1
A vulnerability in the authentication, authorization, and accounting (AAA) security services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause an affected device to reload, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-119
critical
9.8
2018-03-28 CVE-2018-0150 Use of Hard-coded Credentials vulnerability in Cisco IOS XE 16.5.1
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, remote attacker to log in to a device running an affected release of Cisco IOS XE Software with the default username and password that are used at initial boot, aka a Static Credential Vulnerability.
network
low complexity
cisco CWE-798
critical
9.8
2018-03-28 CVE-2018-0151 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XE 16.5.1
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.
network
low complexity
cisco CWE-119
critical
9.8