CVE-2024-20398
- EPSS 0.21%
- Veröffentlicht 11.09.2024 17:15:12
- Zuletzt bearbeitet 03.10.2024 01:47:52
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation...
CVE-2024-20304
- EPSS 0.6%
- Veröffentlicht 11.09.2024 17:15:11
- Zuletzt bearbeitet 03.10.2024 14:20:07
A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device. This vulnerability exists because the Mtrace2 ...
CVE-2024-20456
- EPSS 0.19%
- Veröffentlicht 10.07.2024 16:15:03
- Zuletzt bearbeitet 04.08.2025 17:44:16
A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high privileges to bypass the Cisco Secure Boot functionality and load unverified software on an affected device. To exploit this successfu...
CVE-2024-20319
- EPSS 0.25%
- Veröffentlicht 13.03.2024 17:15:48
- Zuletzt bearbeitet 07.07.2025 15:49:35
A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to bypass configured management plane protection policies and access the Simple Network Management Plane (SNMP) server of an affecte...
CVE-2024-20320
- EPSS 0.19%
- Veröffentlicht 13.03.2024 17:15:48
- Zuletzt bearbeitet 05.08.2025 14:40:07
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series and 5700 Series Routers could allow an authenticated, local attacker to elevate privileges on an af...
CVE-2024-20322
- EPSS 0.49%
- Veröffentlicht 13.03.2024 17:15:48
- Zuletzt bearbeitet 05.08.2025 14:41:53
A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to imprope...
CVE-2024-20327
- EPSS 0.34%
- Veröffentlicht 13.03.2024 17:15:48
- Zuletzt bearbeitet 06.05.2025 17:11:55
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to crash the ppp_ma process, resulting in a denial ...
CVE-2023-44487
- EPSS 100%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.08.2026 19:37:30
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- EPSS 0.09%
- Veröffentlicht 13.09.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:40:38
A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race c...
CVE-2023-20190
- EPSS 0.55%
- Veröffentlicht 13.09.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:40:47
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerab...