Vulnerabilities > Cisco > IOS XR

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-34722 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
6.7
2021-09-09 CVE-2021-34728 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device.
local
low complexity
cisco CWE-78
7.8
2021-09-09 CVE-2021-34737 NULL Pointer Dereference vulnerability in Cisco IOS XR
A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to trigger a crash of the dhcpd process, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-476
7.5
2021-09-09 CVE-2021-34771 Information Exposure vulnerability in Cisco IOS XR
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow.
local
low complexity
cisco CWE-200
5.5
2021-04-08 CVE-2021-1485 Argument Injection or Modification vulnerability in Cisco IOS XR
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges on the underlying Linux operating system (OS) of an affected device.
local
low complexity
cisco CWE-88
7.8
2021-02-04 CVE-2021-1389 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for an interface of an affected device.
network
low complexity
cisco
6.5
2021-02-04 CVE-2021-1370 OS Command Injection vulnerability in Cisco IOS XR
A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running NCS540L software images could allow an authenticated, local attacker to elevate their privilege to root.
local
low complexity
cisco CWE-78
7.2
2021-02-04 CVE-2021-1313 Memory Leak vulnerability in Cisco IOS XR
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco CWE-401
7.5
2021-02-04 CVE-2021-1288 Unspecified vulnerability in Cisco IOS XR
Multiple vulnerabilities in the ingress packet processing function of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
network
low complexity
cisco
7.5
2021-02-04 CVE-2021-1268 Insufficient Adherence to Expected Conventions vulnerability in Cisco IOS XR
A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device.
low complexity
cisco CWE-1076
6.5