Vulnerabilities > Cisco > IOS XR > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-05-02 CVE-2018-0286 Improper Handling of Exceptional Conditions vulnerability in Cisco IOS XR 6.3.1/6.3.2/6.5.1
A vulnerability in the netconf interface of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on affected system.
network
low complexity
cisco CWE-755
5.3
2017-11-30 CVE-2017-12355 Improper Input Validation vulnerability in Cisco IOS XR 6.4.1Base
A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause one of the LPTS processes on an affected system to restart unexpectedly, resulting in a brief denial of service (DoS) condition.
network
low complexity
cisco CWE-20
5.3
2017-07-04 CVE-2017-6719 Improper Input Validation vulnerability in Cisco IOS XR 6.0.2/6.0.2.01
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection.
local
low complexity
cisco CWE-20
6.7
2017-07-04 CVE-2017-6718 Improper Input Validation vulnerability in Cisco IOS XR 6.0.2/6.0.2.01
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges to the root level.
local
low complexity
cisco CWE-20
6.7
2017-06-13 CVE-2017-6666 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the forwarding component of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an authenticated, local attacker to cause the router to stop forwarding data traffic across Traffic Engineering (TE) tunnels, resulting in a denial of service (DoS) condition.
local
low complexity
cisco
6.0
2017-04-07 CVE-2017-6599 Missing Release of Resource after Effective Lifetime vulnerability in Cisco IOS XR 6.1.1/6.2.1
A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash due to a system memory leak, resulting in a denial of service (DoS) condition.
network
low complexity
cisco CWE-772
5.3
2016-10-05 CVE-2016-6421 Resource Management Errors vulnerability in Cisco IOS XR 5.2.2
Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID CSCvb05643.
network
low complexity
cisco CWE-399
5.3
2016-09-18 CVE-2016-1433 Resource Management Errors vulnerability in Cisco IOS XR 6.0.0/6.0.1/6.0Base
Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packets, aka Bug ID CSCuz66289.
network
low complexity
cisco CWE-399
5.3
2016-04-12 CVE-2016-1376 Improper Input Validation vulnerability in Cisco IOS XR
Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548.
network
low complexity
cisco CWE-20
5.3
2016-03-24 CVE-2016-1366 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS XR
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.
network
low complexity
cisco CWE-264
6.5