📦 Ios Xe

by Cisco

🔍 What is Ios Xe?

Cisco IOS XE is Cisco's modern network operating system running on enterprise routers, switches, and wireless controllers deployed across corporate networks, data centers, branch offices, and service provider infrastructure worldwide. As the evolution of Cisco IOS, IOS XE provides a Linux-based modular architecture with advanced security, automation, telemetry, and programmability features supporting Cisco's ASR, ISR, CSR, Catalyst 9000, and other next-generation platforms.

IOS XE serves as the foundation for Software-Defined Access (SD-Access), SD-WAN, network segmentation, zero-trust architecture, and intent-based networking in enterprise environments. The platform supports critical network functions including routing, switching, wireless management, network policy enforcement, application visibility, and integrated security services across campus, branch, WAN, and data center deployments.

Security vulnerabilities in Cisco IOS XE can expose enterprise networks to severe risks including unauthorized administrative access, network compromise, and infrastructure disruption. Common vulnerability categories include authentication bypass in web UI, privilege escalation, command injection, denial-of-service, buffer overflows, and flaws affecting REST API, SNMP, SSH, IPsec VPN, and wireless controller functions. High-severity vulnerabilities have enabled attackers to implant persistent backdoors, steal credentials, intercept traffic, and gain control of network infrastructure.

Organizations deploying Cisco IOS XE should implement defense-in-depth strategies including disabling unused management interfaces (HTTP/HTTPS UI on internet-facing devices), restricting administrative access through ACLs, implementing AAA with TACACS+/RADIUS, enabling logging and monitoring, and maintaining aggressive patch management. Network security teams should prioritize updates for internet-facing devices, VPN concentrators, and wireless controllers which face higher attack exposure.

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20363

CRITICAL CVSS 9.0 Sep 25, 2025

This critical vulnerability allows remote attackers to execute arbitrary code with root privileges on affected Cisco devices. Unauthenticated attackers can exploit Cisco ASA/FTD devices, while authent...

CVE-2025-20188

CRITICAL CVSS 10.0 May 7, 2025

This critical vulnerability in Cisco IOS XE Wireless LAN Controllers allows unauthenticated remote attackers to upload arbitrary files and execute commands with root privileges. Attackers exploit a ha...

CVE-2023-20198

CRITICAL CVSS 10.0 Oct 16, 2023

CVE-2023-20198 is a critical vulnerability in Cisco IOS XE Software web UI that allows unauthenticated attackers to gain initial access and create local user accounts. Combined with CVE-2023-20273, at...

CVE-2021-34770

CRITICAL CVSS 10.0 Sep 23, 2021

This critical vulnerability in Cisco Catalyst 9000 wireless controllers allows unauthenticated remote attackers to execute arbitrary code with administrative privileges or cause denial of service by s...

CVE-2021-1619

CRITICAL CVSS 9.8 Sep 23, 2021

An uninitialized variable in Cisco IOS XE Software's AAA function allows unauthenticated remote attackers to bypass NETCONF/RESTCONF authentication. This enables attackers to manipulate device configu...

CVE-2025-20202

HIGH CVSS 7.4 May 7, 2025

An unauthenticated attacker on the same network segment can send a malicious Cisco Discovery Protocol packet to an access point, causing the wireless controller to crash and reboot. This affects Cisco...

CVE-2025-20154

HIGH CVSS 8.6 May 7, 2025

An out-of-bounds array access vulnerability in Cisco's TWAMP server implementation allows unauthenticated remote attackers to cause device reloads (DoS) by sending crafted TWAMP control packets. Affec...

CVE-2025-20162

HIGH CVSS 8.6 May 7, 2025

A vulnerability in Cisco IOS XE Software's DHCP snooping feature allows unauthenticated remote attackers to cause a denial of service by sending DHCP request packets. This can wedge interface queues, ...

CVE-2025-20140

HIGH CVSS 7.4 May 7, 2025

An unauthenticated adjacent wireless attacker can cause denial of service on Cisco IOS XE WLCs by sending crafted IPv6 packets that trigger memory exhaustion in the wncd daemon. This affects wireless ...

CVE-2025-20172

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS, IOS XE, and IOS XR Software allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. This affects devices with SNMP enabled usin...

CVE-2025-20173

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects devices running vul...

CVE-2025-20174

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects devices running vul...

CVE-2025-20175

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects SNMP versions 1, 2c...

CVE-2025-20176

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. This affects devices running vulnerable softw...

CVE-2025-20170

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. This affects devices running vulnerable Cisco...

CVE-2025-20171

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects SNMP versions 1, 2c...

CVE-2025-20169

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects devices running vul...

CVE-2024-20467

HIGH CVSS 8.6 Sep 25, 2024

An unauthenticated remote attacker can cause Cisco routers to crash and reload by sending specially crafted fragmented IPv4 packets, resulting in denial of service. This affects Cisco ASR 1000 Series ...

CVE-2024-20480

HIGH CVSS 8.6 Sep 25, 2024

An unauthenticated remote attacker can send specially crafted IPv4 DHCP packets to Cisco IOS XE SD-Access fabric edge nodes, causing high CPU utilization that leads to a denial of service requiring ma...

CVE-2024-20436

HIGH CVSS 8.6 Sep 25, 2024

An unauthenticated remote attacker can cause Cisco IOS XE devices to crash and reload by sending crafted HTTP requests to specific URLs when the Telemetry Service feature is enabled. This denial-of-se...

CVE-2024-20455

HIGH CVSS 8.6 Sep 25, 2024

This vulnerability allows unauthenticated remote attackers to cause a denial of service (DoS) by sending crafted traffic through SD-WAN IPsec tunnels on affected Cisco IOS XE devices. The vulnerabilit...

CVE-2024-20433

HIGH CVSS 8.6 Sep 25, 2024

An unauthenticated remote attacker can send specially crafted RSVP packets to vulnerable Cisco devices, causing a buffer overflow that forces the device to reboot. This results in a denial of service ...

CVE-2024-20313

HIGH CVSS 7.4 Apr 24, 2024

An unauthenticated attacker on the same network segment can send specially crafted OSPFv2 packets to vulnerable Cisco IOS XE devices, causing them to crash and reload. This creates a denial-of-service...

CVE-2024-20308

HIGH CVSS 8.6 Mar 27, 2024

A heap underflow vulnerability in Cisco IOS/IOS XE IKEv1 fragmentation handling allows unauthenticated remote attackers to trigger device reloads via crafted UDP packets. This affects systems running ...

CVE-2024-20311

HIGH CVSS 8.6 Mar 27, 2024

An unauthenticated remote attacker can send specially crafted LISP packets to vulnerable Cisco devices, causing them to reload and creating a denial of service condition. This affects Cisco IOS and IO...

CVE-2024-20314

HIGH CVSS 8.6 Mar 27, 2024

This vulnerability in Cisco IOS XE Software's IPv4 SD-Access fabric edge node allows unauthenticated remote attackers to cause a denial of service by sending specially crafted IPv4 packets. Exploitati...

CVE-2024-20271

HIGH CVSS 8.6 Mar 27, 2024

An unauthenticated remote attacker can send specially crafted IPv4 packets to Cisco Access Points, causing them to crash and reload, resulting in denial of service. This affects Cisco APs running vuln...

CVE-2024-20303

HIGH CVSS 7.4 Mar 27, 2024

An unauthenticated attacker on the same wireless network can send continuous mDNS packets to Cisco IOS XE Wireless LAN Controllers, causing high CPU usage that disconnects access points and creates a ...

CVE-2024-20259

HIGH CVSS 8.6 Mar 27, 2024

An unauthenticated remote attacker can send a crafted DHCP request packet to cause Cisco IOS XE devices with DHCP snooping and endpoint analytics enabled to reload unexpectedly, resulting in a denial ...

CVE-2023-20273

HIGH CVSS 7.2 Oct 25, 2023

This vulnerability in Cisco IOS XE Software allows authenticated remote attackers to execute arbitrary commands with root privileges via the web UI. Attackers can exploit insufficient input validation...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2023-20186

HIGH CVSS 8.0 Sep 27, 2023

This vulnerability allows authenticated remote attackers with level 15 privileges to bypass AAA command authorization checks when using SCP, enabling them to copy files to/from affected Cisco devices....

CVE-2023-20227

HIGH CVSS 8.6 Sep 27, 2023

An unauthenticated remote attacker can send crafted L2TP packets to vulnerable Cisco IOS XE devices, causing them to reload unexpectedly and creating a denial of service condition. This affects Cisco ...

CVE-2023-20033

HIGH CVSS 8.6 Sep 27, 2023

This vulnerability in Cisco Catalyst 3650 and 3850 Series Switches running IOS XE allows unauthenticated remote attackers to cause a denial of service by sending high-rate traffic to the management in...

CVE-2023-20065

HIGH CVSS 7.8 Mar 23, 2023

This vulnerability allows an authenticated local attacker to escape the Cisco IOx application container and execute arbitrary commands with root privileges on Cisco IOS XE devices. It affects systems ...

CVE-2023-20067

HIGH CVSS 7.4 Mar 23, 2023

An unauthenticated attacker on the same network can send crafted traffic through a wireless access point to exploit insufficient input validation in Cisco IOS XE WLCs, causing high CPU utilization and...

CVE-2023-20080

HIGH CVSS 8.6 Mar 23, 2023

An unauthenticated remote attacker can send crafted DHCPv6 messages to Cisco IOS/IOS XE devices with DHCPv6 relay or server features enabled, causing the device to reload unexpectedly due to insuffici...

CVE-2023-20076

HIGH CVSS 7.2 Feb 12, 2023

This vulnerability in Cisco IOx allows authenticated remote attackers to execute arbitrary commands as root on the host operating system by deploying a malicious application with a crafted activation ...

CVE-2022-20678

HIGH CVSS 8.6 Apr 15, 2022

This vulnerability allows unauthenticated remote attackers to cause Cisco IOS XE devices with AppNav-XE feature enabled to reload, resulting in denial of service. Attackers can exploit it by sending c...

CVE-2022-20681

HIGH CVSS 7.8 Apr 15, 2022

This vulnerability allows authenticated local attackers on Cisco Catalyst 9000 switches and wireless controllers to escalate privileges to level 15 (administrative) by executing specific CLI commands....

CVE-2022-20683

HIGH CVSS 8.6 Apr 15, 2022

This vulnerability allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending crafted packets from the wired network to a wireless client, leading to a crash and reload of...

CVE-2022-20692

HIGH CVSS 7.7 Apr 15, 2022

This vulnerability allows authenticated remote attackers with low privileges to cause denial of service on Cisco IOS XE devices by exhausting resources through excessive NETCONF over SSH connections. ...

CVE-2021-34768

HIGH CVSS 8.6 Sep 23, 2021

This vulnerability allows unauthenticated remote attackers to crash Cisco Catalyst 9000 wireless controllers by sending malformed CAPWAP packets, causing denial of service. It affects Cisco IOS XE Sof...

CVE-2021-34714

HIGH CVSS 7.4 Sep 23, 2021

This vulnerability allows an unauthenticated attacker on the same network segment to send specially crafted UDLD packets to Cisco networking devices, causing them to reload and creating a denial of se...

CVE-2021-34699

HIGH CVSS 7.7 Sep 23, 2021

This vulnerability in Cisco IOS and IOS XE software allows authenticated remote attackers to trigger a device reload via a specific CLI command through the web UI, causing a denial of service (DoS). I...

CVE-2025-20197

MEDIUM CVSS 6.7 May 7, 2025

This vulnerability allows authenticated local attackers with privilege level 15 access on Cisco IOS XE devices to elevate their privileges to root on the underlying operating system. Attackers can exp...

CVE-2025-20199

MEDIUM CVSS 4.6 May 7, 2025

This vulnerability allows authenticated local attackers with privilege level 15 access on Cisco IOS XE devices to escalate privileges to root on the underlying operating system. Attackers can exploit ...

CVE-2025-20201

MEDIUM CVSS 6.7 May 7, 2025

This vulnerability allows authenticated local attackers with privilege level 15 access on Cisco IOS XE devices to escalate privileges to root on the underlying operating system. Attackers can exploit ...

CVE-2025-20193

MEDIUM CVSS 6.5 May 7, 2025

This vulnerability allows authenticated low-privileged remote attackers to perform OS command injection through Cisco IOS XE's web management interface, potentially reading sensitive files from the un...

CVE-2025-20195

MEDIUM CVSS 4.3 May 7, 2025

This CSRF vulnerability in Cisco IOS XE web management interface allows unauthenticated remote attackers to trick authenticated users into executing CLI commands. Attackers can clear syslog, parser, a...

CVE-2025-20190

MEDIUM CVSS 6.5 May 7, 2025

This vulnerability in Cisco IOS XE Wireless Controller Software allows authenticated lobby ambassador users to delete arbitrary user accounts, including administrative accounts, by sending crafted HTT...

CVE-2023-20100

MEDIUM CVSS 6.8 Mar 23, 2023

An unauthenticated remote attacker can cause denial of service on Cisco wireless controllers by exploiting a logic error in the CAPWAP AP joining process. The attacker needs to add a malicious AP to t...

CVE-2023-20056

MEDIUM CVSS 6.5 Mar 23, 2023

This vulnerability allows authenticated local attackers to cause Cisco access points to reboot by submitting specially crafted CLI commands. It affects Cisco APs running vulnerable software versions. ...

CVE-2023-20082

MEDIUM CVSS 6.1 Mar 23, 2023

This vulnerability in Cisco Catalyst 9300 switches allows authenticated local attackers with level-15 privileges or unauthenticated attackers with physical access to execute persistent code at boot ti...

CVE-2023-20029

MEDIUM CVSS 4.4 Mar 23, 2023

This vulnerability in Cisco IOS XE Software allows authenticated local attackers to gain root privileges by exploiting insufficient memory protection in the Meraki onboarding feature. Attackers can mo...