Vulnerabilities > Cisco > IOS XR > 7.10

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-20390 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) on XML TCP listen port 38751. This vulnerability is due to a lack of proper error validation of ingress XML packets.
network
low complexity
cisco
5.3
2024-09-11 CVE-2024-20406 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of ingress IS-IS packets.
low complexity
cisco
7.4
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2023-09-13 CVE-2023-20135 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Cisco IOS XR
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition when an install query regarding an ISO image is performed during an install operation that uses an ISO image.
local
high complexity
cisco CWE-367
7.0
2023-09-13 CVE-2023-20191 Incorrect Authorization vulnerability in Cisco IOS XR
A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to incomplete support for this feature.
network
low complexity
cisco CWE-863
7.5
2023-09-13 CVE-2023-20236 Insufficient Verification of Data Authenticity vulnerability in Cisco IOS XR
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated, local attacker to install an unverified software image on an affected device. This vulnerability is due to insufficient image verification.
local
low complexity
cisco CWE-345
7.8
2021-09-23 CVE-2021-34714 Improper Input Validation vulnerability in Cisco products
A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload.
low complexity
cisco CWE-20
7.4