Vulnerabilities > Cisco > IOS XR > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-09-13 CVE-2023-20190 Incorrect Authorization vulnerability in Cisco IOS XR
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is due to incorrect destination address range encoding in the compression module of an ACL that is applied to an interface of an affected device.
network
low complexity
cisco CWE-863
5.3
2023-09-13 CVE-2023-20233 Improper Validation of Integrity Check Value vulnerability in Cisco IOS XR
A vulnerability in the Connectivity Fault Management (CFM) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect processing of invalid continuity check messages (CCMs).
network
low complexity
cisco CWE-354
6.5
2023-03-09 CVE-2023-20064 Missing Authorization vulnerability in Cisco IOS XR
A vulnerability in the GRand Unified Bootloader (GRUB) for Cisco IOS XR Software could allow an unauthenticated attacker with physical access to the device to view sensitive files on the console using the GRUB bootloader command line.
low complexity
cisco CWE-862
4.6
2022-05-26 CVE-2022-20821 Information Exposure vulnerability in Cisco IOS XR
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container.
network
low complexity
cisco CWE-200
6.5
2022-04-15 CVE-2022-20758 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
network
high complexity
cisco
6.8
2021-09-09 CVE-2021-34708 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XR
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system.
local
low complexity
cisco CWE-347
6.7
2021-09-09 CVE-2021-34709 Improper Verification of Cryptographic Signature vulnerability in Cisco IOS XR
Multiple vulnerabilities in image verification checks of Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for Cisco 8000 Series Routers could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system.
local
high complexity
cisco CWE-347
6.4
2021-09-09 CVE-2021-34721 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
6.7
2021-09-09 CVE-2021-34722 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
6.7
2021-09-09 CVE-2021-34771 Information Exposure vulnerability in Cisco IOS XR
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow.
local
low complexity
cisco CWE-200
5.5