Ios Xr

Vendor:

First CVE: Aug 3, 2005 · Active for 20 years

196
Total CVEs
More Total CVEs than 100% of tracked products
8.9
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
5.1%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ios Xr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2005
20 years ago
Most Recent CVE
Mar 11, 2026
139 days ago

CVE Severity & Scoring

Ios Xr196 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local35 (17.9%)
Network75 (38.3%)
Unknown63 (32.1%)
Physical1 (0.5%)
Adjacent Network22 (11.2%)
Attack Complexity
Low122 (62.2%)
High11 (5.6%)
Unknown63 (32.1%)
User Interaction
None129 (65.8%)
Unknown63 (32.1%)
Required4 (2.0%)
Privileges Required
Low26 (13.3%)
High16 (8.2%)
None91 (46.4%)
Unknown63 (32.1%)

Top CVEs

Signals from CVEs in this product scope (196 CVEs).

196 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote a
Sep 19, 20167.597YESYES
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a relo
Feb 5, 20208.871YESNO
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow a
Mar 28, 20188.868YESNO
A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi contai
May 26, 20226.567YESNO
A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory
Aug 29, 20208.667YESNO
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peer
Aug 30, 20107.565YESNO
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthentic
Mar 28, 20188.064YESNO
Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immedi
Sep 23, 20208.659YESNO
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wil
Aug 19, 20095.958YESNO

Exploit Exposure

Signals from CVEs in this product scope (196 CVEs).

CISA KEV
10 CVEs
5.1% of CVEs· 98th percentile
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
1.5% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (196 CVEs).

Media Mentions

Signals from CVEs in this product scope (196 CVEs).

Top CNAs Publishing CVEs For Ios Xr

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.9.21117.50.4%00
7.9.2157.30.4%00
7.9.1147.30.4%00
7.9.016.50.3%00
7.915.30.5%00
7.8.2338.60.6%00
7.8.22117.50.4%00
7.8.2147.30.4%00
7.8.1257.60.5%00
7.8.1147.30.4%00
7.7.21137.20.4%00
7.7.2147.30.4%00
7.7.1147.30.4%00
7.717.51.1%00
7.6.348.40.5%00
7.6.2127.20.4%00
7.6.1567.30.5%00
7.6.1137.00.5%00
7.5.5247.70.5%00
7.5.5117.20.4%00