Vulnerabilities > Cisco > IOS XR > 6.5.1

DATE CVE VULNERABILITY TITLE RISK
2021-02-04 CVE-2021-1128 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attacker to view more information than their privileges allow.
local
low complexity
cisco
5.5
2020-11-12 CVE-2020-26070 Improper Resource Shutdown or Release vulnerability in Cisco IOS XR
A vulnerability in the ingress packet processing function of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-404
8.6
2020-11-06 CVE-2020-3284 Unspecified vulnerability in Cisco products
A vulnerability in the enhanced Preboot eXecution Environment (PXE) boot loader for Cisco IOS XR 64-bit Software could allow an unauthenticated, remote attacker to execute unsigned code during the PXE boot process on an affected device.
network
low complexity
cisco
critical
9.8
2020-09-23 CVE-2020-3569 Allocation of Resources Without Limits or Throttling vulnerability in Cisco IOS XR
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash.
network
low complexity
cisco CWE-770
8.6
2020-09-04 CVE-2020-3530 Incorrect Authorization vulnerability in Cisco IOS XR
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to execute that command, even though administrative privileges should be required.
local
low complexity
cisco CWE-863
8.4
2020-09-04 CVE-2020-3473 Incorrect Authorization vulnerability in Cisco IOS XR
A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local CLI shell user to elevate privileges and gain full administrative control of the device.
local
low complexity
cisco CWE-863
7.8
2020-08-17 CVE-2020-3449 Improper Check for Unusual or Exceptional Conditions vulnerability in Cisco IOS XR
A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent authorized users from monitoring the BGP status and cause the BGP process to stop processing new updates, resulting in a denial of service (DOS) condition.
network
low complexity
cisco CWE-754
4.3
2019-11-26 CVE-2019-15998 Missing Authorization vulnerability in Cisco IOS XR 6.5.1/6.5.2/6.5.3
A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device.
network
low complexity
cisco CWE-862
5.3
2019-09-25 CVE-2019-12709 OS Command Injection vulnerability in Cisco IOS XR
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with root privileges.
local
low complexity
cisco CWE-78
6.7
2019-08-07 CVE-2019-1910 Improper Input Validation vulnerability in Cisco IOS XR
A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routing protocol functionality in Cisco IOS XR Software could allow an unauthenticated attacker who is in the same IS–IS area to cause a denial of service (DoS) condition.
low complexity
cisco CWE-20
7.4