Ios Xr
Vendor:
First CVE: Aug 3, 2005 · Active for 20 years
196
Total CVEs
More Total CVEs than 100% of tracked products
8.9
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 37% of tracked products
5.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ios Xr over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 3, 2005
20 years ago
Most Recent CVE
Mar 11, 2026
139 days ago
CVE Severity & Scoring
Ios Xr196 CVEs
48%
49%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local35 (17.9%)
Network75 (38.3%)
Unknown63 (32.1%)
Physical1 (0.5%)
Adjacent Network22 (11.2%)
Attack Complexity
Low122 (62.2%)
High11 (5.6%)
Unknown63 (32.1%)
User Interaction
None129 (65.8%)
Unknown63 (32.1%)
Required4 (2.0%)
Privileges Required
Low26 (13.3%)
High16 (8.2%)
None91 (46.4%)
Unknown63 (32.1%)
Top CVEs
Signals from CVEs in this product scope (196 CVEs).
196 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2016-6415HIGH The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote a | Sep 19, 2016 | 7.5 | 97 | YES | YES |
CVE-2020-3118HIGH A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a relo | Feb 5, 2020 | 8.8 | 71 | YES | NO |
CVE-2018-0167HIGH Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow a | Mar 28, 2018 | 8.8 | 68 | YES | NO |
CVE-2022-20821MEDIUM A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi contai | May 26, 2022 | 6.5 | 67 | YES | NO |
CVE-2020-3566HIGH A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust process memory | Aug 29, 2020 | 8.6 | 67 | YES | NO |
CVE-2010-3035HIGH Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peer | Aug 30, 2010 | 7.5 | 65 | YES | NO |
CVE-2018-0175HIGH Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthentic | Mar 28, 2018 | 8.0 | 64 | YES | NO |
CVE-2020-3569HIGH Multiple vulnerabilities in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to either immedi | Sep 23, 2020 | 8.6 | 59 | YES | NO |
CVE-2009-2055MEDIUM Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wil | Aug 19, 2009 | 5.9 | 58 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (196 CVEs).
CISA KEV
10 CVEs
5.1% of CVEs· 98th percentile
Metasploit
1 CVE
0.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
1.5% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (196 CVEs).
Media Mentions
Signals from CVEs in this product scope (196 CVEs).
Top CNAs Publishing CVEs For Ios Xr
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.9.21 | 11 | 7.5 | 0.4% | 0 | 0 |
| 7.9.2 | 15 | 7.3 | 0.4% | 0 | 0 |
| 7.9.1 | 14 | 7.3 | 0.4% | 0 | 0 |
| 7.9.0 | 1 | 6.5 | 0.3% | 0 | 0 |
| 7.9 | 1 | 5.3 | 0.5% | 0 | 0 |
| 7.8.23 | 3 | 8.6 | 0.6% | 0 | 0 |
| 7.8.22 | 11 | 7.5 | 0.4% | 0 | 0 |
| 7.8.2 | 14 | 7.3 | 0.4% | 0 | 0 |
| 7.8.12 | 5 | 7.6 | 0.5% | 0 | 0 |
| 7.8.1 | 14 | 7.3 | 0.4% | 0 | 0 |
| 7.7.21 | 13 | 7.2 | 0.4% | 0 | 0 |
| 7.7.2 | 14 | 7.3 | 0.4% | 0 | 0 |
| 7.7.1 | 14 | 7.3 | 0.4% | 0 | 0 |
| 7.7 | 1 | 7.5 | 1.1% | 0 | 0 |
| 7.6.3 | 4 | 8.4 | 0.5% | 0 | 0 |
| 7.6.2 | 12 | 7.2 | 0.4% | 0 | 0 |
| 7.6.15 | 6 | 7.3 | 0.5% | 0 | 0 |
| 7.6.1 | 13 | 7.0 | 0.5% | 0 | 0 |
| 7.5.52 | 4 | 7.7 | 0.5% | 0 | 0 |
| 7.5.5 | 11 | 7.2 | 0.4% | 0 | 0 |