Ios Xe
Vendor:
First CVE: Jul 30, 2009 · Active for 16 years
541
Total CVEs
More Total CVEs than 100% of tracked products
31.8
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
5.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ios Xe over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2009
16 years ago
Most Recent CVE
Sep 25, 2025
305 days ago
CVE Severity & Scoring
Ios Xe541 CVEs
35%
62%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local76 (14.0%)
Network282 (52.1%)
Unknown116 (21.4%)
Physical9 (1.7%)
Adjacent Network58 (10.7%)
Attack Complexity
Low393 (72.6%)
High32 (5.9%)
Unknown116 (21.4%)
User Interaction
None404 (74.7%)
Unknown116 (21.4%)
Required21 (3.9%)
Privileges Required
Low88 (16.3%)
High81 (15.0%)
None256 (47.3%)
Unknown116 (21.4%)
Top CVEs
Signals from CVEs in this product scope (541 CVEs).
541 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-20198CRITICAL Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and | Oct 16, 2023 | 10.0 | 99 | YES | YES |
CVE-2017-3881CRITICAL A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a rel | Mar 17, 2017 | 9.8 | 99 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2016-6415HIGH The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote a | Sep 19, 2016 | 7.5 | 97 | YES | YES |
CVE-2023-20273HIGH A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is d | Oct 25, 2023 | 7.2 | 96 | YES | YES |
CVE-2017-6736HIGH The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to rem | Jul 17, 2017 | 8.8 | 94 | YES | YES |
CVE-2025-20352HIGH A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following:
An authenticated, remote | Sep 24, 2025 | 7.7 | 85 | YES | NO |
CVE-2017-6737HIGH A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could | Jul 17, 2017 | 8.8 | 84 | YES | NO |
CVE-2018-0151CRITICAL A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of servi | Mar 28, 2018 | 9.8 | 75 | YES | NO |
CVE-2017-6742HIGH A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could | Jul 17, 2017 | 8.8 | 75 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (541 CVEs).
CISA KEV
28 CVEs
5.2% of CVEs· 97th percentile
Metasploit
4 CVEs
0.7% of CVEs· 96th percentile
Nuclei
3 CVEs
0.6% of CVEs· 96th percentile
ExploitDB
5 CVEs
0.9% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (541 CVEs).
Media Mentions
Signals from CVEs in this product scope (541 CVEs).
Top CNAs Publishing CVEs For Ios Xe
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| fuji-16.8.1 | 1 | 7.5 | 2.0% | 0 | 0 |
| fuji-16.7.1 | 1 | 7.5 | 2.0% | 0 | 0 |
| everest-16.6.1 | 1 | 8.6 | 3.8% | 0 | 0 |
| denali-16.3.4 | 1 | 8.6 | 7.8% | 1 | 0 |
| denali-16.3.3 | 2 | 7.5 | 2.3% | 0 | 0 |
| denali-16.3.1 | 1 | 7.5 | 3.9% | 0 | 0 |
| 99.9.0z | 1 | 7.5 | 3.8% | 0 | 0 |
| 5.2.0.base | 1 | 8.8 | 3.4% | 1 | 0 |
| 3.9s_3.9.2s | 2 | 6.7 | 2.5% | 0 | 0 |
| 3.9s_3.9.1s | 2 | 6.7 | 2.5% | 0 | 0 |
| 3.9s_3.9.1as | 2 | 6.7 | 2.5% | 0 | 0 |
| 3.9s_3.9.0s | 2 | 6.7 | 2.5% | 0 | 0 |
| 3.9s_3.9.0as | 2 | 6.7 | 2.5% | 0 | 0 |
| 3.9s\(.2\) | 3 | 7.8 | 3.0% | 0 | 0 |
| 3.9s.2 | 8 | 7.8 | 2.8% | 0 | 0 |
| 3.9s\(.1\) | 3 | 7.8 | 3.0% | 0 | 0 |
| 3.9s.1 | 8 | 7.8 | 2.8% | 0 | 0 |
| 3.9s\(.0\) | 3 | 7.8 | 3.0% | 0 | 0 |
| 3.9s.0 | 8 | 7.8 | 2.8% | 0 | 0 |
| 3.9s | 2 | 7.6 | 1.7% | 0 | 0 |