Cisco
Cisco IOS XE Sd-wan: vulnerabilidades y CVE
Cisco IOS XE Sd-wan tiene 26 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses0
Críticas5
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-20352 | Alta (7.7) | 39% | ⚠ Explotación activa | 24 sept 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-20352 | Alta (7.7) | 39% | ⚠ Explotación activa | 24 sept 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a… |
| CVE-2025-20151 | Media (4.3) | 0.41% | — | 7 may 2025 | A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to poll an… |
| CVE-2024-20373 | Media (5.3) | 0.50% | — | 15 nov 2024 | This vulnerability exists because Cisco IOS Software and Cisco IOS XE Software do not support extended IPv4 ACLs for SNMP, but they do allow administrators to configure extended named IPv4 ACLs that are attached to the… |
| CVE-2024-20455 | Alta (8.6) | 0.66% | — | 25 sept 2024 | A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a… |
| CVE-2023-20035 | Alta (7.8) | 0.22% | — | 23 mar 2023 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation… |
| CVE-2022-20850 | Alta (7.1) | 0.21% | — | 30 sept 2022 | A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenticated, local attacker to delete arbitrary files from the file system of an affected device. This… |
| CVE-2021-1529 | Alta (7.8) | 0.31% | — | 21 oct 2021 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by… |
| CVE-2021-34729 | Media (6.7) | 0.36% | — | 23 sept 2021 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This… |
| CVE-2021-34727 | Crítica (9.8) | 2.6% | — | 23 sept 2021 | A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds… |
| CVE-2021-34725 | Media (6.7) | 0.36% | — | 23 sept 2021 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This… |
| CVE-2021-34724 | Media (6) | 0.27% | — | 23 sept 2021 | A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to elevate privileges and execute arbitrary code on the underlying operating system as the root user. An attacker must… |
| CVE-2021-1619 | Crítica (9.1) | 1.8% | — | 23 sept 2021 | A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of… |
| CVE-2021-1371 | Media (6.6) | 0.25% | — | 24 mar 2021 | A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when… |
| CVE-2021-1454 | Media (6.7) | 0.28% | — | 24 mar 2021 | Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to… |
| CVE-2021-1432 | Alta (7.3) | 0.34% | — | 24 mar 2021 | A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be… |
| CVE-2021-1383 | Media (6.7) | 0.59% | — | 24 mar 2021 | Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to… |
| CVE-2021-1241 | Alta (7.5) | 1.4% | — | 20 ene 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,… |
| CVE-2021-1305 | Media (4.3) | 1.3% | — | 20 ene 2021 | Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system,… |
| CVE-2021-1301 | Crítica (9.8) | 2.1% | — | 20 ene 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section… |
| CVE-2021-1300 | Crítica (9.8) | 2.1% | — | 20 ene 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute attacks against an affected device. For more information about these vulnerabilities, see the Details section… |
| CVE-2021-1279 | Alta (8.6) | 1.4% | — | 20 ene 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,… |
| CVE-2021-1278 | Alta (7.5) | 1.7% | — | 20 ene 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,… |
| CVE-2021-1274 | Alta (8.6) | 1.9% | — | 20 ene 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,… |
| CVE-2021-1273 | Alta (8.6) | 1.4% | — | 20 ene 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities,… |
| CVE-2020-3375 | Crítica (9.8) | 3.9% | — | 31 jul 2020 | A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker… |
| CVE-2020-3216 | Media (6.8) | 0.43% | — | 3 jun 2020 | A vulnerability in Cisco IOS XE SD-WAN Software could allow an unauthenticated, physical attacker to bypass authentication and gain unrestricted access to the root shell of an affected device. The vulnerability exists… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.