Vulnerabilities > Cisco > IOS XE > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-0480 Race Condition vulnerability in Cisco IOS XE 3.6(5)
A vulnerability in the errdisable per VLAN feature of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause the device to crash, leading to a denial of service (DoS) condition.
high complexity
cisco CWE-362
6.1
2018-10-05 CVE-2018-0477 OS Command Injection vulnerability in Cisco IOS XE 15.3(3)S3.16/16.7.1/16.7(1)
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
local
low complexity
cisco CWE-78
6.7
2018-10-05 CVE-2018-0476 Unspecified vulnerability in Cisco IOS XE 15.5(3)S5.1/15.5(3)S6.1/16.6.2
A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
high complexity
cisco
5.9
2018-10-05 CVE-2018-0469 Double Free vulnerability in Cisco IOS XE 16.5.1
A vulnerability in the web user interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
high complexity
cisco CWE-415
6.8
2018-10-05 CVE-2018-0466 Unspecified vulnerability in Cisco IOS and IOS XE
A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload.
low complexity
cisco
6.5
2018-10-05 CVE-2018-0197 Improper Input Validation vulnerability in Cisco IOS and IOS XE
A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to corrupt the internal VTP database on an affected device and cause a denial of service (DoS) condition.
low complexity
cisco CWE-20
6.5
2018-08-14 CVE-2018-0131 Inadequate Encryption Strength vulnerability in Cisco IOS and IOS XE
A vulnerability in the implementation of RSA-encrypted nonces in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to obtain the encrypted nonces of an Internet Key Exchange Version 1 (IKEv1) session.
network
high complexity
cisco CWE-326
5.9
2018-04-19 CVE-2018-0257 Unspecified vulnerability in Cisco IOS XE
A vulnerability in Cisco IOS XE Software running on Cisco cBR Series Converged Broadband Routers could allow an unauthenticated, adjacent attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
low complexity
cisco
4.3
2018-03-28 CVE-2018-0196 Unspecified vulnerability in Cisco IOS XE 16.1.2/16.2.0/16.3(1)
A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to write arbitrary files to the operating system of an affected device.
network
low complexity
cisco
4.9
2018-03-28 CVE-2018-0190 Cross-site Scripting vulnerability in Cisco IOS XE
Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software.
network
low complexity
cisco CWE-79
6.1