Known vulnerabilities in Cisco IOS XR - page 3

Software: Cisco IOS XR
Software CPE: cpe:2.3:o:cisco_systems:cisco_ios_xr:*:*:*:*:*:*:*:*
Total vulnerabilities: 105
Public exploits: 1
Known exploited (KEV): 5
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco IOS XR Cisco IOS XR is affected by 105 known vulnerabilities: 1 critical, 18 high, 44 medium, 41 low Critical High Medium Low

Vulnerabilities (105)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU87521 - Improper Access Control
CVE-2024-20322
CWE-284 Medium
No
No
7.11.2 14.03.2024 SB2024031419
#VU87520 - Improper Access Control
CVE-2024-20315
CWE-284 Medium
No
No
7.10.2 14.03.2024 SB2024031418
#VU80775 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2023-20135
CWE-367 Low
No
No
7.10.1 14.09.2023 SB2023091421
#VU80773 - Improper Verification of Cryptographic Signature
CVE-2023-20236
CWE-347 Low
No
No
7.10.1 14.09.2023 SB2023091420
#VU80771 - NULL Pointer Dereference
CVE-2023-20233
CWE-476 Low
No
No
7.5.4, 7.6.3, 7.7.21, 7.8.2, 7.9.1 14.09.2023 SB2023091419
#VU80769 - Permissions, Privileges, and Access Controls
CVE-2023-20190
CWE-264 Medium
No
No
7.3.5, 7.5.4, 7.8.2, 7.9.1 14.09.2023 SB2023091418
#VU80767 - Improper Access Control
CVE-2023-20191
CWE-284 High
No
No
7.7.21, 7.9.2, 7.10.1 14.09.2023 SB2023091417
#VU73203 - Improper input validation
CVE-2023-20049
CWE-20 High
No
No
7.5.3, 7.6.2, 7.7.1 09.03.2023 SB2023030930
#VU73202 - Exposure of sensitive information to an unauthorized actor
CVE-2023-20064
CWE-200 Low
No
No
7.6.1, 7.7.1, 7.9.1 09.03.2023 SB2023030928
#VU67389 - Improper input validation
CVE-2022-20849
CWE-20 Low
No
No
7.5.2 15.09.2022 SB2022091508
#VU67388 - Uncontrolled Memory Allocation
CVE-2022-20845
CWE-789 Low
No
No
6.5.32 15.09.2022 SB2022091507
#VU67372 - Buffer overflow
CVE-2022-20846
CWE-120 Medium
No
No
7.5.2, 7.6.2, 7.7.1 15.09.2022 SB2022091503
#VU63500 - Improper Access Control
CVE-2022-20821
CWE-284 Medium
No
Exploited
7.3.4 21.05.2022 SB2022052101
#VU62350 - Resource Management Errors
CVE-2022-20758
CWE-399 Medium
No
No
7.3.2, 7.4.2 15.04.2022 SB2022041509
#VU62348 - Out-of-bounds read
CVE-2022-20714
CWE-125 High
No
No
7.3.2 15.04.2022 SB2022041507
#VU59955 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-20655
CWE-78 Low
No
No
7.0.2, 7.1.1 24.01.2022 SB2022012410
SB2022012512
#VU56875 - Improper input validation
CVE-2021-34714
CWE-20 Medium
No
No
6.7.4, 6.8.1, 7.2.2, 7.3.1, 7.3.15, 7.4.1 24.09.2021 SB2021092427
#VU56433 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-34728
CWE-78 Low
No
No
7.3.2, 7.4.1 09.09.2021 SB2021090915
#VU56432 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-34719
CWE-78 Low
No
No
6.8.1, 7.3.2, 7.4.1 09.09.2021 SB2021090915
#VU56431 - NULL Pointer Dereference
CVE-2021-34737
CWE-476 Medium
No
No
6.8.1, 7.3.2, 7.4.1 09.09.2021 SB2021090914


Showing elements 41 - 60 out of 105