Cisco Vulnerabilities and Affected Products
Vulnerabilities associated with IOS XR.
Products
Clear product- Cisco Small Business RV Series Router Firmware262 vulnerabilities
- Cisco IOS XE Software248 vulnerabilities
- Cisco Firepower Threat Defense Software161 vulnerabilities
- Cisco Adaptive Security Appliance (ASA) Software160 vulnerabilities
- Cisco Identity Services Engine Software156 vulnerabilities
- Cisco Firepower Management Center128 vulnerabilities
- Cisco IOS XR Software107 vulnerabilities
- Cisco NX-OS Software88 vulnerabilities
- Cisco Data Center Network Manager74 vulnerabilities
- Cisco SD-WAN vManage61 vulnerabilities
- Cisco SD-WAN Solution54 vulnerabilities
- Cisco Unified Communications Manager52 vulnerabilities
- Cisco Prime Infrastructure50 vulnerabilities
- Cisco Secure Firewall Threat Defense (FTD) Software48 vulnerabilities
- Cisco Webex Meetings46 vulnerabilities
- Cisco Catalyst SD-WAN Manager45 vulnerabilities
- IOS41 vulnerabilities
- Cisco Enterprise NFV Infrastructure Software39 vulnerabilities
- Cisco IOS36 vulnerabilities
- Cisco Unified Contact Center Express36 vulnerabilities
- Cisco WebEx WRF Player35 vulnerabilities
- Cisco Digital Network Architecture Center (DNA Center)33 vulnerabilities
- Cisco Unified Computing System (Managed)33 vulnerabilities
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software31 vulnerabilities
- Cisco Unity Connection31 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-20363CRITICAL | Cisco IOS XR Heap-based Buffer OverflowA vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper valid… CWE-122Sep 25, 2025 | CVSS9.0v3.1 | EPSS7.52% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-20821MEDIUM | Cisco IOS XR Software Health Check Open Port VulnerabilityA vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon activation. An attacker could exploit this vulnerability by connecting to the Redis instance on the open port. A successful exploit could allow the attacker to write to the Redis in-memory database, write arbitrary files to … | CVSS6.5v3.1 | EPSS12.1% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-3569HIGH | Cisco IOS XR Software DVMRP Memory Exhaustion VulnerabilitiesMultiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immediately crash the Internet Group Management Protocol (IGMP) process or make it consume available memory and eventually crash. The memory consumption may negatively impact other processes that are running on the device. These vulnerabilities are due to the incorrect handling of IGMP packets. An attacker could exploit thes… | CVSS8.6v3.1 | EPSS3.32% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-3566HIGH | Cisco IOS XR Software DVMRP Memory Exhaustion VulnerabilityA vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory of an affected device. The vulnerability is due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An attacker could exploit this vulnerability by sending crafted IGMP traffic to an affected device. A successful exploit could allow the attacker to cause memory exhaustion, resulting… | CVSS8.6v3.1 | EPSS3.7% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-3118HIGH | Cisco IOS XR Software Cisco Discovery Protocol Format String VulnerabilityA vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of string input from certain fields in Cisco Discovery Protocol messages. An attacker could exploit this vulnerability by sending a malicious Cisco Discovery Protocol packet to an affected device. A successful exploit could allow the attacker to … | CVSS8.8v3.1 | EPSS11.7% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2010-3035HIGH | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service VulnerabilityCisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211. CWE-20Aug 30, 2010 | CVSS7.5v3.1 | EPSS5.56% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2009-2055MEDIUM | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service VulnerabilityCisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009. CWE-20Aug 19, 2009 | CVSS5.9v3.1 | EPSS3.33% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |