Known vulnerabilities in Cisco IOS XR

Software: Cisco IOS XR
Software CPE: cpe:2.3:o:cisco_systems:cisco_ios_xr:*:*:*:*:*:*:*:*
Total vulnerabilities: 105
Public exploits: 1
Known exploited (KEV): 5
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco IOS XR Cisco IOS XR is affected by 105 known vulnerabilities: 1 critical, 18 high, 44 medium, 41 low Critical High Medium Low

Vulnerabilities (105)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124029 - Permissions, Privileges, and Access Controls
CVE-2026-20046
CWE-264 Low
No
No
25.2.2 16.03.2026 SB2026031632
#VU124028 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-20040
CWE-78 Low
No
No
24.2.1, 24.2.2, 24.2.11, 24.2.20, 24.2.21, 24.3.1, 24.3.2, 24.3.20, 24.3.30, 24.4.1, 24.4.2, 24.4.10, 24.4.15, 24.4.30, 25.1.1, 25.1.2, 25.1.30, 25.2.1, 25.2.2, 25.2.15, 25.2.30, 25.3.1, 25.4.1, 26.1.1 16.03.2026 SB2026031632
#VU123907 - Improper Validation of Specified Type of Input
CVE-2026-20074
CWE-1287 Medium
No
No
25.1.30, 25.2.2, 25.3.1, 25.4.1, 26.1.1 12.03.2026 SB2026031202
#VU123906 - Improper Cleanup on Thrown Exception
CVE-2026-20118
CWE-460 Medium
No
No
7.9.2 CSCws66900, 7.10.2 CSCws66892, 7.11.2 CSCws66900, 7.11.21 CSCws66900, 24.1.2 CSCws66892, 24.2.2 CSCws66892, 24.2.21 CSCws36724, 24.2.21 CSCws66900, 24.3.2 CSCws66900, 24.4.2 CSCws66900 12.03.2026 SB2026031201
#VU116120 - Heap-based Buffer Overflow
CVE-2025-20363
CWE-122 Critical
No
No
- 25.09.2025 SB2025092573
SB2025092574
SB2025092575
#VU115158 - Improper Access Control
CVE-2025-20159
CWE-284 Medium
No
No
24.2.21, 24.3.1, 25.1.1, 25.1.2, 25.2.1 11.09.2025 SB2025091127
#VU115157 - Resource exhaustion
CVE-2025-20340
CWE-400 Medium
No
No
24.2.21, 25.1.2, 25.2.1 11.09.2025 SB2025091126
#VU115156 - Improper Verification of Cryptographic Signature
CVE-2025-20248
CWE-347
No
No
24.2.21, 24.3.20, 24.3.30, 24.4.2, 24.4.30, 25.1.1, 25.1.2, 25.2.1 11.09.2025 SB2025091125
#VU108835 - Improper input validation
CVE-2025-20154
CWE-20 High
No
No
24.3.2, 24.3.20, 24.4.1, 24.4.2, 24.4.10, 25.1.1 09.05.2025 SB2025050934
#VU105699 - Permissions, Privileges, and Access Controls
CVE-2025-20177
CWE-264 Low
No
No
7.11.21, 24.2.2, 24.2.20, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031338
#VU105698 - Memory corruption
CVE-2025-20115
CWE-119 High
No
No
24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031337
#VU105697 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-20138
CWE-78 Low
No
No
7.11.21, 24.2.2, 24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031333
#VU105696 - Permissions, Privileges, and Access Controls
CVE-2025-20145
CWE-264 Medium
No
No
7.11.21, 24.2.2, 24.2.20, 24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031333
#VU105693 - Improper input validation
CVE-2025-20146
CWE-20 High
No
No
24.4.1 13.03.2025 SB2025031336
#VU105692 - Improper Access Control
CVE-2025-20144
CWE-284 Medium
No
No
6.2.1, 7.11.2, 7.11.21, 24.1.1, 24.1.2, 24.2.1, 24.2.2, 24.2.11, 24.2.20, 24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031335
#VU105691 - Allocation of Resources Without Limits or Throttling
CVE-2025-20141
CWE-770 Medium
No
No
6.6.2, 6.6.3, 6.6.4, 6.6.25, 6.7.1, 6.7.2, 6.7.3, 6.7.4, 6.7.35, 6.8.1, 6.8.2, 6.9.1, 6.9.2, 7.0.1, 7.0.2, 7.0.90, 7.1.1, 7.1.2, 7.1.3, 7.1.15, 7.1.25, 7.2.0, 7.2.1, 7.2.2, 7.2.12, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.15, 7.3.16, 7.3.25, 7.3.26, 7.3.27, 7.4.1, 7.4.2, 7.4.15, 7.4.16, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.5.5, 7.5.12, 7.6.1, 7.6.2, 7.6.3, 7.6.15, 7.7.1, 7.7.2, 7.7.21, 7.8.1, 7.8.2, 7.8.22, 7.8.23, 7.9.1, 7.9.2, 7.10.1, 7.10.2, 7.11.1, 7.11.2, 7.11.21, 24.1.1, 24.1.2, 24.2.1, 24.2.2, 24.2.11, 24.2.20, 24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031334
#VU105690 - Allocation of Resources Without Limits or Throttling
CVE-2025-20209
CWE-770 High
No
No
7.11.21, 24.2.2, 24.2.20, 24.3.1, 24.3.2, 24.3.20, 24.4.1, 24.4.10 13.03.2025 SB2025031333
#VU105678 - Improper Verification of Cryptographic Signature
CVE-2025-20143
CWE-347 Low
No
No
7.9.1 12.03.2025 SB2025031278
#VU105677 - Improper input validation
CVE-2025-20142
CWE-20 Medium
No
No
7.9.21, 7.10.2 12.03.2025 SB2025031277
#VU103675 - Error Handling
CVE-2025-20169
CWE-388 Medium
No
No
24.2.21, 24.4.2, 25.2.1 06.02.2025 SB2025020624
SB2025020625


Showing elements 1 - 20 out of 105