Known vulnerabilities in Cisco IOS XE SD-WAN

Software CPE: cpe:2.3:a:cisco_systems:cisco_ios_xe_sd-wan:*:*:*:*:*:*:*:*
Total vulnerabilities: 24
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco IOS XE SD-WAN Cisco IOS XE SD-WAN is affected by 24 known vulnerabilities: 3 high, 5 medium, 16 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU108840 - Exposure of sensitive information to an unauthorized actor
CVE-2025-20221
CWE-200 Medium
No
No
17.9.7a, 17.12.5a, 17.15.2a 09.05.2025 SB2025050937
#VU73987 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-20035
CWE-78 Low
No
No
17.6.4, 17.6.5, 17.9.1, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1a, 17.9.2, 17.9.2a, 17.9.3, 17.10.1, 17.10.1a, 17.10.1b 23.03.2023 SB2023032342
#VU67748 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-20850
CWE-22 Low
No
No
16.10.1 29.09.2022 SB2022092928
#VU59955 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-20655
CWE-78 Low
No
No
16.10.2, 16.12.1 b, 17.2.1r 24.01.2022 SB2022012410
SB2022012512
#VU57590 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-1529
CWE-78 Low
No
No
17.2.3, 17.3.4, 17.4.2, 17.5.1a, 17.6.1 21.10.2021 SB2021102131
#VU56872 - Command injection
CVE-2021-34725
CWE-77 Low
No
No
16.12(3.28), 16.12.4, 17.2(1.38), 17.2.2, 17.3(0.165), 17.3.1, 17.4(0.26), 17.4.1, 17.4.1 b, 18.4.6, 19.2.3, 19.2.4, 19.2.31, 20.1.2, 20.1.12, 20.3.1, 20.3.2, 20.3.2.1, 20.3.3, 20.3.3.1, 20.4.1, 20.4.1.1 24.09.2021 SB2021092424
#VU56868 - UNIX Symbolic Link (Symlink) Following
CVE-2021-1612
CWE-61 Low
No
No
17.3.4 24.09.2021 SB2021092420
#VU56863 - Command injection
CVE-2021-34729
CWE-77 Low
No
No
16.12.5, 17.2.3, 17.3.1a, 17.3.2, 17.3.3, 17.3.4a, 17.4.1a, 17.4.2, 17.5.1a, 17.6.1a 24.09.2021 SB2021092415
#VU56862 - Memory corruption
CVE-2021-34727
CWE-119 High
No
No
16.12(3.16), 16.12.4, 17.2(1.16), 17.2.2, 17.3(0.131), 17.3.1, 18.4.5, 18.4.6, 19.2.3, 19.2.4, 19.2.31, 20.1.2, 20.1.12, 20.3.1, 20.3.2, 20.3.2.1, 20.3.3, 20.3.3.1, 20.4.1, 20.4.1.1 24.09.2021 SB2021092414
#VU56861 -
CVE-2021-34723
Low
No
No
17.3.3, 17.3.4a, 17.4.2, 17.5.1a, 17.6.1a 24.09.2021 SB2021092413
#VU56835 - Improper Access Control
CVE-2021-34724
CWE-284 Low
No
No
17.3.3, 17.3.4a, 17.4.2, 17.5.1a 23.09.2021 SB2021092306
#VU51784 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-1432
CWE-78 Low
No
No
16.8.1, 16.8.1c, 16.8.1d, 16.8.1e, 16.8.1s, 16.8.1a, 16.8.1 b, 16.8.2, 16.8.3, 16.9.1, 16.9.1c, 16.9.1d, 16.9.1s, 16.9.1a, 16.9.1 b, 16.9.2, 16.9.2s, 16.9.2a, 16.9.3, 16.9.3h, 16.9.3s, 16.9.3a, 16.9.4, 16.9.4c, 16.9.5, 16.9.5f, 16.9.6, 16.9.7, 16.10.1, 16.10.1c, 16.10.1d, 16.10.1e, 16.10.1f, 16.10.1g, 16.10.1i, 16.10.1s, 16.10.1a, 16.10.1 b, 16.10.2, 16.10.3, 16.12.4.43, 16.12.5, 16.12.5a, 17.2.1.64, 17.2.2, 17.3.0.213, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.1.9, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.62, 17.4.0.65, 17.4.1, 17.4.1a, 17.4.1 b 30.03.2021 SB2021033013
#VU51783 - Improper input validation
CVE-2021-1431
CWE-20 Medium
No
No
16.12.4.57, 16.12.5, 16.12.5a, 17.2.2.1, 17.3.0.220, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.1.17, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.83, 17.4.1, 17.4.1a, 17.4.1 b 30.03.2021 SB2021033012
#VU51782 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-1436
CWE-22 Low
No
No
16.12.4.39, 16.12.5, 16.12.5a, 17.1.3, 17.3.0.211, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.1.9, 17.3.2, 17.3.2a, 17.3.3, 17.3.3a, 17.4.0.62, 17.4.1, 17.4.1a, 17.4.1 b 30.03.2021 SB2021033011
#VU51773 - Improper input validation
CVE-2021-1454
CWE-20 Low
No
No
16.12.1, 16.12.5.20, 17.2.1.183, 17.3.2.6, 17.3.3, 17.4.0.216, 17.4.1.38, 17.5.0.143, 17.6.0.16 29.03.2021 SB2021032921
#VU51772 - Improper input validation
CVE-2021-1383
CWE-20 Low
No
No
16.12.1, 16.12.5.20, 17.2.1.183, 17.3.2.6, 17.3.3, 17.4.0.216, 17.4.1.38, 17.5.0.143, 17.6.0.16 29.03.2021 SB2021032921
#VU51735 - Resource Management Errors
CVE-2021-1281
CWE-399 Low
No
No
- 26.03.2021 SB2021032601
#VU51719 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-1382
CWE-78 Low
No
No
- 25.03.2021 SB2021032510
#VU50013 - NULL Pointer Dereference
CVE-2021-1274
CWE-476 Medium
No
No
16.12.4 20.01.2021 SB2021012618
#VU49898 - Memory corruption
CVE-2021-1300
CWE-119 High
No
No
16.12.4 20.01.2021 SB2021012109


Showing elements 1 - 20 out of 24