Vulnerabilities > Cisco > IOS XR

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-0175 Use of Externally-Controlled Format String vulnerability in Cisco Ios, IOS XE and IOS XR
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
low complexity
cisco CWE-134
8.0
2018-03-28 CVE-2018-0167 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco Ios, IOS XE and IOS XR
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
low complexity
cisco CWE-119
8.8
2018-01-31 CVE-2018-0136 Unspecified vulnerability in Cisco IOS XR 5.3.4
A vulnerability in the IPv6 subsystem of Cisco IOS XR Software Release 5.3.4 for the Cisco Aggregation Services Router (ASR) 9000 Series could allow an unauthenticated, remote attacker to trigger a reload of one or more Trident-based line cards, resulting in a denial of service (DoS) condition.
network
low complexity
cisco
8.6
2017-11-30 CVE-2017-12355 Improper Input Validation vulnerability in Cisco IOS XR 6.4.1Base
A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause one of the LPTS processes on an affected system to restart unexpectedly, resulting in a brief denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2017-10-05 CVE-2017-12270 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XR
A vulnerability in the gRPC code of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition when the emsd service stops.
network
low complexity
cisco CWE-119
7.5
2017-07-10 CVE-2017-6731 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco IOS XR 4.3.2.Mcast/6.0.2.Base
A vulnerability in Multicast Source Discovery Protocol (MSDP) ingress packet processing for Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the MSDP session to be unexpectedly reset, causing a short denial of service (DoS) condition.
network
low complexity
cisco CWE-119
7.5
2017-07-10 CVE-2017-6728 Improper Privilege Management vulnerability in Cisco IOS XR
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary code at the root privilege level on an affected system, because of Incorrect Permissions.
local
high complexity
cisco CWE-269
7.0
2017-07-04 CVE-2017-6719 Improper Input Validation vulnerability in Cisco IOS XR 6.0.2/6.0.2.01
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection.
local
low complexity
cisco CWE-20
6.7
2017-07-04 CVE-2017-6718 Improper Input Validation vulnerability in Cisco IOS XR 6.0.2/6.0.2.01
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level.
local
low complexity
cisco CWE-20
6.7
2017-06-13 CVE-2017-6666 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) tunnels, resulting in a denial of service (DoS) condition.
local
low complexity
cisco
6.0