Known vulnerabilities in Cisco IOS XR 24.4
Vendor:
Cisco Systems, Inc
Software:
Cisco IOS XR
Version:
24.4
Software CPE:
cpe:2.3:o:cisco_systems:cisco_ios_xr:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
12
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
26.3.1
26.2.2
26.2.1
26.1.2
25.4.2
25.2.21
24.4.15
25.2.15
25.2.30
25.1.30
7.10.2 CSCws66892
24.2.2 CSCws66892
24.1.2 CSCws66892
7.11.21 CSCws66900
24.3.2 CSCws66900
24.2.21 CSCws66900
24.2.21 CSCws36724
24.4.2 CSCws66900
7.9.2 CSCws66900
7.11.2 CSCws66900
26.1.1
25.4.1
25.2.2
25.3.1
25.2
25.1
24.3.30
24.4.30
25.1.2
25.1.1
24.4
24.3
6.7.35
7.3.6
7.3.16
7.3.25
7.3.26
7.3.27
7.4.15
7.4.16
7.5.5
7.5.12
7.6.15
7.8.22
24.2.20
24.3.20
24.4.10
24.2
24.2.21
25.2.1
24.4.2
24.4.1
24.3.2
7.8.23
24.2.11
24.1.2
7.8.1
7.7.2
6.9.2
6.9.1
6.8.2
7.11.21
24.2.2
24.3.1
24.2.1
7.11.2
7.10.2
24.1.1
24.1
7.11.1
7.9.21
7.11
7.6.3
7.8.2
7.5.4
7.3.5
7.10.1
7.9.2
7.7.21
7.10
7.9
7.8
6.5
7.5.3
7.9.1
6.5.32
7.7.1
7.7.0
7.6.2
7.6.1
7.6.0
7.5.2
7.5.1
7.5.0
7.3.4
7.3.3
7.4.2
7.1
6.7
6.1
6.0
6.7.4
7.3.15
7.3.0
4.3.0
6.8.1
6.8
7.4.1
7.4
7.3.2
7.3
6.6.4
7.0.14
6.4.2 (SMU)
6.6.3 (SMU)
6.5.2 (SMU)
5.2.6
5.2.47
5.3.4
6.1.12
6.1.21
6.1.22
6.1.31
6.1.32
6.1.33
6.1.42
6.1.45
6.2.2
6.3.1
6.4.0
6.5.1
6.5.15
6.5.90
6.5.92
6.5.93
5.1.3 (SMU)
5.3.2 (SMU)
5.3.3 (SMU)
6.7.2
6.7.3
7.1.25
7.2.2
7.2.12
6.6
7.0
6.6.12
ncs540l-7.0.1.CSCvr78185
iosxrwbd-6.6.12.CSCvr78185
xrv9k-6.5.3.CSCvr78185
ncs5500-6.5.3.CSCvr78185
ncs5k-6.5.3.CSCvr78185
ncs560-6.6.25.CSCvr78185
ncs540-6.5.3.CSCvr78185
asr9k-x64-6.5.3.CSCvr78185
asr9k-px-6.5.3.CSCvr78185
hfr-px-6.4.2.CSCvr78185
asr9k-px-6.4.2.CSCvr78185
ncs6k-5.2.5.CSCvr78185
5.0.0
6.7.1
7.0.90
7.1.15
7.2.0
7.1.2
7.3.1
7.2.1
7.1.3
7.1.1
7.0.2
6.4.3
6.5.3
6.5.2
6.4.2
6.3.3
6.3.2
6.3.15
6.2.3
6.2.25
6.1.4
6.1.3
5.2.5
4.3.2
6.6.3
7.0.1
6.6.25
6.6.2
6.6.1
6.4.1
6.0.2
4.3.2.MCAST
6.2.1
6.1.2
6.1.1
-
5.3.3
5.3.2
5.3.1
5.3.0
5.2.4
5.2.3
5.2.2
5.2.1
5.2.0
5.1.3
5.1.2
5.1.1
5.1.0
6.0.1
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146765 - Incorrect Calculation CVE-2026-20275 |
CWE-682 | High | 26.2.2, 26.3.1 | 02.09.2026 |
SB2026090283 |
||
| #VU146766 - Insufficient Control Flow Management CVE-2026-20276 |
CWE-691 | High | 26.2.2, 26.3.1 | 02.09.2026 |
SB2026090283 |
||
| #VU146767 - Protection Mechanism Failure CVE-2026-20277 |
CWE-693 | High | 26.2.2, 26.3.1 | 02.09.2026 |
SB2026090283 |
||
| #VU146768 - Improper Neutralization CVE-2026-20278 |
CWE-707 | High | 26.2.2, 26.3.1 | 02.09.2026 |
SB2026090283 |
||
| #VU146769 - Improper Access Control CVE-2026-20279 |
CWE-284 | High | 26.2.2, 26.3.1 | 02.09.2026 |
SB2026090283 |
||
| #VU146770 - Improper Check or Handling of Exceptional Conditions CVE-2026-20280 |
CWE-703 | High | 26.2.2, 26.3.1 | 02.09.2026 |
SB2026090283 |
||
| #VU146764 - Improper control of a resource through its lifetime CVE-2026-20274 |
CWE-664 | High | 26.2.2, 26.3.1 | 02.09.2026 |
SB2026090283 |
||
| #VU123907 - Improper Validation of Specified Type of Input CVE-2026-20074 |
CWE-1287 | Medium | 25.1.30, 25.2.2, 25.3.1, 25.4.1, 26.1.1 | 12.03.2026 |
SB2026031202 |
||
| #VU123906 - Improper Cleanup on Thrown Exception CVE-2026-20118 |
CWE-460 | Medium | 7.9.2 CSCws66900, 7.10.2 CSCws66892, 7.11.2 CSCws66900, 7.11.21 CSCws66900, 24.1.2 CSCws66892, 24.2.2 CSCws66892, 24.2.21 CSCws36724, 24.2.21 CSCws66900, 24.3.2 CSCws66900, 24.4.2 CSCws66900 | 12.03.2026 |
SB2026031201 |
||
| #VU115157 - Resource exhaustion CVE-2025-20340 |
CWE-400 | Medium | 24.2.21, 25.1.2, 25.2.1 | 11.09.2025 |
SB2025091126 |
||
| #VU115156 - Improper Verification of Cryptographic Signature CVE-2025-20248 |
CWE-347 | 24.2.21, 24.3.20, 24.3.30, 24.4.2, 24.4.30, 25.1.1, 25.1.2, 25.2.1 | 11.09.2025 |
SB2025091125 |
|||
| #VU105699 - Permissions, Privileges, and Access Controls CVE-2025-20177 |
CWE-264 | Low | 7.11.21, 24.2.2, 24.2.20, 24.3.2, 24.3.20, 24.4.1, 24.4.10 | 13.03.2025 |
SB2025031338 |