Known vulnerabilities in Cisco IOS XE SD-WAN
Vendor:
Cisco Systems, Inc
Software:
Cisco IOS XE SD-WAN
Software CPE:
cpe:2.3:a:cisco_systems:cisco_ios_xe_sd-wan:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
24
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
17.9.7a
17.12.5a
17.15.2a
16.11.1a
16.10.5
16.10.4
16.12.1e
16.12.1d
17.15.1a
17.14.1a
17.13.1a
17.12.4
17.12.3
17.12.2
17.12.1a
17.11.1a
17.9.5a
17.9.4a
17.9.4
17.9.3a
17.8.1a
17.7.2
17.7.1a
17.7.1
17.6.7
17.6.6a
17.6.6
17.6.5a
17.6.3a
17.6.2
20.4.1.2
17.3.8a
17.3.8
17.3.7
17.3.6
17.3.5
17.2.1v
17.09.04a.0.6
17.09.04.0.5180
17.06.05.0.5797
17.10.1
17.10.1a
17.10.1b
17.6.4
17.6.5
17.9.1
17.9.1a
17.9.1w
17.9.1x
17.9.1x1
17.9.2
17.9.2a
17.9.3
16.12.1b
17.6
17.5
17.4
17.6.1
16.12(3.28)
17.2(1.38)
17.3(0.165)
17.4(0.26)
17.3.4
17.2.3
20.3
20.2.0
20.2
20.1.0
20.1
19.2.99
19.2.0
16.12(3.16)
17.2(1.16)
17.3(0.131)
18.4.5
18.4.6
19.2.3
19.2.4
19.2.31
20.1.2
20.1.12
20.3.1
20.3.2
20.3.2.1
20.3.3
20.3.3.1
20.4.1
20.4.1.1
Gibraltar-16.12.4
sdwan-18.4.5
sdwan-19.2.3
sdwan-20.1(1.8)
sdwan-20.1(1.53)
sdwan-20.1.2
sdwan-20.1.12
sdwan-20.3(0.42)
sdwan-20.3(0.374)
sdwan-20.3(0.388)
sdwan-20.3(1.25)
sdwan-20.3.1
sdwan-20.3.2
sdwan-20.4(0.110)
sdwan-20.4(0.393)
sdwan-20.4.1
sdwan-20.5.1
sdwan-20.5(999.421)
17.6.1a
17.3.4a
17.4.2
17.5.1a
16.8.1e
16.8.1d
16.8.1c
16.8.1b
16.8.1a
16.8.1
16.8.1s
16.8.2
16.8.3
16.9.1b
16.9.1a
16.9.1s
16.9.1d
16.9.1c
16.9.2s
16.9.2a
16.9.2
16.9.3a
16.9.3
16.9.3s
16.9.3h
16.9.4c
16.9.4
16.9.5f
16.9.5
16.9.6
16.9.7
16.10.1d
16.10.1c
16.10.1b
16.10.1a
16.10.1
16.10.1s
16.10.1i
16.10.1g
16.10.1f
16.10.1e
16.10.2
16.10.3
16.12(4.43)
17.2(1.64)
17.2.2
17.3(0.213)
17.4(0.65)
Amsterdam-17.2.2
16.12(4.57)
17.2(2.1)
17.3(0.220)
17.3(1.17)
17.4(0.83)
16.12(4.39)
16.12.5
16.12.5a
17.1.3
17.3(0.211)
17.3(1.9)
17.3.1x
17.3.1w
17.3.1a
17.3.1
17.3.2a
17.3.3a
17.4(0.62)
17.4.1a
Amsterdam-17.1.3
Amsterdam-17.3.1
Bengaluru-17.4.1
Gibraltar-16.12.5
16.12(5.20)
17.2(1.183)
17.3(2.6)
17.3.3
17.4(0.216)
17.4(1.38)
17.4.1b
17.5(0.143)
17.6(0.16)
Bengaluru-17.4.1b
16.9.1
17.4.1
17.3
17.3.2
16.12.4
16.12.2r
17.2
16.12
16.10
16.9
17.2.1r
16.12.3
16.12.1
16.11
Vulnerabilities (24)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU108840 - Exposure of sensitive information to an unauthorized actor CVE-2025-20221 |
CWE-200 | Medium | 17.9.7a, 17.12.5a, 17.15.2a | 09.05.2025 |
SB2025050937 |
||
| #VU73987 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2023-20035 |
CWE-78 | Low | 17.6.4, 17.6.5, 17.9.1, 17.9.1w, 17.9.1x, 17.9.1x1, 17.9.1a, 17.9.2, 17.9.2a, 17.9.3, 17.10.1, 17.10.1a, 17.10.1b | 23.03.2023 |
SB2023032342 |
||
| #VU67748 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2022-20850 |
CWE-22 | Low | 16.10.1 | 29.09.2022 |
SB2022092928 |
||
| #VU59955 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2022-20655 |
CWE-78 | Low | 16.10.2, 16.12.1 b, 17.2.1r | 24.01.2022 |
SB2022012410 SB2022012512 |
||
| #VU57590 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-1529 |
CWE-78 | Low | 17.2.3, 17.3.4, 17.4.2, 17.5.1a, 17.6.1 | 21.10.2021 |
SB2021102131 |
||
| #VU56872 - Command injection CVE-2021-34725 |
CWE-77 | Low | 16.12(3.28), 16.12.4, 17.2(1.38), 17.2.2, 17.3(0.165), 17.3.1, 17.4(0.26), 17.4.1, 17.4.1 b, 18.4.6, 19.2.3, 19.2.4, 19.2.31, 20.1.2, 20.1.12, 20.3.1, 20.3.2, 20.3.2.1, 20.3.3, 20.3.3.1, 20.4.1, 20.4.1.1 | 24.09.2021 |
SB2021092424 |
||
| #VU56868 - UNIX Symbolic Link (Symlink) Following CVE-2021-1612 |
CWE-61 | Low | 17.3.4 | 24.09.2021 |
SB2021092420 |
||
| #VU56863 - Command injection CVE-2021-34729 |
CWE-77 | Low | 16.12.5, 17.2.3, 17.3.1a, 17.3.2, 17.3.3, 17.3.4a, 17.4.1a, 17.4.2, 17.5.1a, 17.6.1a | 24.09.2021 |
SB2021092415 |
||
| #VU56862 - Memory corruption CVE-2021-34727 |
CWE-119 | High | 16.12(3.16), 16.12.4, 17.2(1.16), 17.2.2, 17.3(0.131), 17.3.1, 18.4.5, 18.4.6, 19.2.3, 19.2.4, 19.2.31, 20.1.2, 20.1.12, 20.3.1, 20.3.2, 20.3.2.1, 20.3.3, 20.3.3.1, 20.4.1, 20.4.1.1 | 24.09.2021 |
SB2021092414 |
||
| #VU56861 - CVE-2021-34723 |
Low | 17.3.3, 17.3.4a, 17.4.2, 17.5.1a, 17.6.1a | 24.09.2021 |
SB2021092413 |
|||
| #VU56835 - Improper Access Control CVE-2021-34724 |
CWE-284 | Low | 17.3.3, 17.3.4a, 17.4.2, 17.5.1a | 23.09.2021 |
SB2021092306 |
||
| #VU51784 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-1432 |
CWE-78 | Low | 16.8.1, 16.8.1c, 16.8.1d, 16.8.1e, 16.8.1s, 16.8.1a, 16.8.1 b, 16.8.2, 16.8.3, 16.9.1, 16.9.1c, 16.9.1d, 16.9.1s, 16.9.1a, 16.9.1 b, 16.9.2, 16.9.2s, 16.9.2a, 16.9.3, 16.9.3h, 16.9.3s, 16.9.3a, 16.9.4, 16.9.4c, 16.9.5, 16.9.5f, 16.9.6, 16.9.7, 16.10.1, 16.10.1c, 16.10.1d, 16.10.1e, 16.10.1f, 16.10.1g, 16.10.1i, 16.10.1s, 16.10.1a, 16.10.1 b, 16.10.2, 16.10.3, 16.12.4.43, 16.12.5, 16.12.5a, 17.2.1.64, 17.2.2, 17.3.0.213, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.1.9, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.62, 17.4.0.65, 17.4.1, 17.4.1a, 17.4.1 b | 30.03.2021 |
SB2021033013 |
||
| #VU51783 - Improper input validation CVE-2021-1431 |
CWE-20 | Medium | 16.12.4.57, 16.12.5, 16.12.5a, 17.2.2.1, 17.3.0.220, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.1.17, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.83, 17.4.1, 17.4.1a, 17.4.1 b | 30.03.2021 |
SB2021033012 |
||
| #VU51782 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-1436 |
CWE-22 | Low | 16.12.4.39, 16.12.5, 16.12.5a, 17.1.3, 17.3.0.211, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.1.9, 17.3.2, 17.3.2a, 17.3.3, 17.3.3a, 17.4.0.62, 17.4.1, 17.4.1a, 17.4.1 b | 30.03.2021 |
SB2021033011 |
||
| #VU51773 - Improper input validation CVE-2021-1454 |
CWE-20 | Low | 16.12.1, 16.12.5.20, 17.2.1.183, 17.3.2.6, 17.3.3, 17.4.0.216, 17.4.1.38, 17.5.0.143, 17.6.0.16 | 29.03.2021 |
SB2021032921 |
||
| #VU51772 - Improper input validation CVE-2021-1383 |
CWE-20 | Low | 16.12.1, 16.12.5.20, 17.2.1.183, 17.3.2.6, 17.3.3, 17.4.0.216, 17.4.1.38, 17.5.0.143, 17.6.0.16 | 29.03.2021 |
SB2021032921 |
||
| #VU51735 - Resource Management Errors CVE-2021-1281 |
CWE-399 | Low | - | 26.03.2021 |
SB2021032601 |
||
| #VU51719 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2021-1382 |
CWE-78 | Low | - | 25.03.2021 |
SB2021032510 |
||
| #VU50013 - NULL Pointer Dereference CVE-2021-1274 |
CWE-476 | Medium | 16.12.4 | 20.01.2021 |
SB2021012618 |
||
| #VU49898 - Memory corruption CVE-2021-1300 |
CWE-119 | High | 16.12.4 | 20.01.2021 |
SB2021012109 |
Showing elements 1 - 20 out of 24