Vulnerabilities > Cisco > IOS XR > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-34721 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
6.7
2021-09-09 CVE-2021-34722 OS Command Injection vulnerability in Cisco IOS XR
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges.
local
low complexity
cisco CWE-78
6.7
2021-09-09 CVE-2021-34771 Information Exposure vulnerability in Cisco IOS XR
A vulnerability in the Cisco IOS XR Software CLI could allow an authenticated, local attacker to view more information than their privileges allow.
local
low complexity
cisco CWE-200
5.5
2021-02-04 CVE-2021-1389 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the IPv6 traffic processing of Cisco IOS XR Software and Cisco NX-OS Software for certain Cisco devices could allow an unauthenticated, remote attacker to bypass an IPv6 access control list (ACL) that is configured for an interface of an affected device.
network
low complexity
cisco
6.5
2021-02-04 CVE-2021-1268 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the IPv6 protocol handling of the management interfaces of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause an IPv6 flood on the management interface network of an affected device.
low complexity
cisco
6.5
2021-02-04 CVE-2021-1244 Unspecified vulnerability in Cisco IOS XR
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device.
local
low complexity
cisco
6.7
2021-02-04 CVE-2021-1136 Unspecified vulnerability in Cisco IOS XR
Multiple vulnerabilities in Cisco Network Convergence System (NCS) 540 Series Routers, only when running Cisco IOS XR NCS540L software images, and Cisco IOS XR Software for the Cisco 8000 Series Routers could allow an authenticated, local attacker to execute unsigned code during the boot process on an affected device.
local
low complexity
cisco
6.7
2021-02-04 CVE-2021-1128 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local attacker to view more information than their privileges allow.
local
low complexity
cisco
5.5
2020-08-17 CVE-2020-3449 Improper Check for Unusual or Exceptional Conditions vulnerability in Cisco IOS XR
A vulnerability in the Border Gateway Protocol (BGP) additional paths feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to prevent authorized users from monitoring the BGP status and cause the BGP process to stop processing new updates, resulting in a denial of service (DOS) condition.
network
low complexity
cisco CWE-754
4.3
2020-06-18 CVE-2020-3364 Incorrect Authorization vulnerability in Cisco IOS XR
A vulnerability in the access control list (ACL) functionality of the standby route processor management interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to reach the configured IP addresses on the standby route processor management Gigabit Ethernet Management interface.
network
low complexity
cisco CWE-863
5.3