📦 Ios Xr

by Cisco

🔍 What is Ios Xr?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20363

CRITICAL CVSS 9.0 Sep 25, 2025

This critical vulnerability allows remote attackers to execute arbitrary code with root privileges on affected Cisco devices. Unauthenticated attackers can exploit Cisco ASA/FTD devices, while authent...

CVE-2020-3284

CRITICAL CVSS 9.8 Nov 6, 2020

This vulnerability allows an unauthenticated remote attacker to execute unsigned code during the PXE boot process on affected Cisco IOS XR devices. Attackers can exploit this by compromising or impers...

CVE-2025-20154

HIGH CVSS 8.6 May 7, 2025

An out-of-bounds array access vulnerability in Cisco's TWAMP server implementation allows unauthenticated remote attackers to cause device reloads (DoS) by sending crafted TWAMP control packets. Affec...

CVE-2025-20146

HIGH CVSS 8.6 Mar 12, 2025

An unauthenticated remote attacker can cause denial of service on affected Cisco routers by sending crafted IPv4 multicast packets to line cards with ACLs or QoS policies applied. This vulnerability a...

CVE-2025-20209

HIGH CVSS 7.5 Mar 12, 2025

An unauthenticated remote attacker can send malformed IKEv2 packets to Cisco IOS XR devices, causing them to stop processing all control plane UDP packets. This results in a denial of service conditio...

CVE-2025-20115

HIGH CVSS 8.6 Mar 12, 2025

A memory corruption vulnerability in Cisco IOS XR's BGP confederation implementation allows unauthenticated remote attackers to cause denial of service. Attackers can exploit this by sending crafted B...

CVE-2025-20138

HIGH CVSS 8.8 Mar 12, 2025

This vulnerability in Cisco IOS XR Software allows an authenticated, low-privileged local attacker to execute arbitrary commands as root on the underlying OS by exploiting insufficient validation of u...

CVE-2025-20141

HIGH CVSS 7.4 Mar 12, 2025

An unauthenticated adjacent attacker can send specially crafted packets to Cisco IOS XR devices, causing control plane traffic to stop working. This affects Cisco IOS XR Software Release 7.9.2 on mult...

CVE-2025-20142

HIGH CVSS 8.6 Mar 12, 2025

This vulnerability in Cisco IOS XR Software allows unauthenticated remote attackers to cause line card resets by sending crafted IPv4 packets to interfaces with IPv4 ACL or QoS policies applied. This ...

CVE-2025-20172

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS, IOS XE, and IOS XR Software allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. This affects devices with SNMP enabled usin...

CVE-2024-20483

HIGH CVSS 7.2 Sep 11, 2024

This vulnerability allows authenticated attackers with Administrator privileges on Cisco Routed PON Manager or direct MongoDB access to execute arbitrary commands as root on the PON Controller contain...

CVE-2024-20381

HIGH CVSS 8.8 Sep 11, 2024

This vulnerability allows authenticated remote attackers to bypass authorization checks in the JSON-RPC API of affected Cisco products, enabling unauthorized configuration changes. Attackers could cre...

CVE-2024-20398

HIGH CVSS 8.8 Sep 11, 2024

This vulnerability in Cisco IOS XR Software allows authenticated local attackers with low-privileged accounts to gain root-level file system access through crafted CLI commands. Attackers can read and...

CVE-2024-20304

HIGH CVSS 8.6 Sep 11, 2024

This vulnerability in Cisco IOS XR Software allows unauthenticated remote attackers to send crafted Mtrace2 packets that exhaust UDP packet memory, causing denial of service. Affected devices become u...

CVE-2024-20320

HIGH CVSS 7.8 Mar 13, 2024

This vulnerability allows authenticated local attackers with low privileges on affected Cisco routers to elevate their privileges to root by exploiting insufficient argument validation in the SSH clie...

CVE-2024-20327

HIGH CVSS 7.4 Mar 13, 2024

An unauthenticated adjacent attacker can crash the ppp_ma process on Cisco ASR 9000 routers running IOS XR with BNG and PPPoE termination, causing denial of service for PPPoE traffic. This affects rou...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2023-20049

HIGH CVSS 8.6 Mar 9, 2023

An unauthenticated remote attacker can send crafted IPv4 BFD packets to cause line card resets on affected Cisco routers, resulting in denial of service. This affects Cisco ASR 9000, ASR 9902, and ASR...

CVE-2022-20714

HIGH CVSS 8.6 Apr 15, 2022

This vulnerability allows unauthenticated remote attackers to cause Cisco ASR 9000 Series routers with Lightspeed-Plus line cards to reset by sending specially crafted IPv4 or IPv6 packets. This resul...

CVE-2021-34714

HIGH CVSS 7.4 Sep 23, 2021

This vulnerability allows an unauthenticated attacker on the same network segment to send specially crafted UDLD packets to Cisco networking devices, causing them to reload and creating a denial of se...

CVE-2021-34719

HIGH CVSS 7.8 Sep 9, 2021

This vulnerability allows authenticated local users with low privileges to execute arbitrary commands with elevated privileges on Cisco IOS XR devices. Attackers can exploit command injection flaws in...

CVE-2021-34728

HIGH CVSS 7.8 Sep 9, 2021

This vulnerability allows authenticated local attackers with low-privileged accounts to elevate their privileges on Cisco IOS XR devices. Attackers can execute arbitrary commands with root-level acces...

CVE-2021-34713

HIGH CVSS 7.4 Sep 9, 2021

An unauthenticated attacker on the same network segment can send specially crafted Ethernet frames to Cisco ASR 9000 routers running vulnerable IOS XR software, causing affected line cards to reboot d...

CVE-2025-20145

MEDIUM CVSS 5.8 Mar 12, 2025

This vulnerability allows unauthenticated remote attackers to bypass egress ACLs on Cisco IOS XR devices when traffic flows between different line cards. Network administrators using affected Cisco IO...

CVE-2025-20177

MEDIUM CVSS 6.7 Mar 12, 2025

This vulnerability allows authenticated local attackers with root-system privileges on Cisco IOS XR devices to bypass image signature verification during boot. Attackers can manipulate boot configurat...

CVE-2025-20143

MEDIUM CVSS 6.7 Mar 12, 2025

This vulnerability allows authenticated local attackers with root-system privileges on Cisco IOS XR devices to bypass Secure Boot integrity checks and load unverified software during boot. It affects ...

CVE-2022-20846

MEDIUM CVSS 4.3 Nov 15, 2024

A heap buffer overflow vulnerability in Cisco Discovery Protocol (CDP) implementation for Cisco IOS XR Software allows unauthenticated adjacent attackers to cause the CDP process to reload. This affec...

CVE-2024-20343

MEDIUM CVSS 5.5 Sep 11, 2024

This vulnerability in Cisco IOS XR Software allows authenticated local attackers with valid credentials to read any file on the underlying Linux file system. Attackers need low-privileged access to th...

CVE-2024-20456

MEDIUM CVSS 6.7 Jul 10, 2024

This vulnerability allows authenticated local attackers with root-system privileges on Cisco IOS XR devices to bypass Secure Boot functionality and load unverified software. The flaw exists in the sof...