Skip to content
COOEY

FAIL › dossier

IOS and IOS XE

PRODUCT

· dossier confidence 40%

Cisco IOS and IOS XE operate as the foundational software for Cisco networking infrastructure but suffer from a persistent pattern of high-severity remote code execution vulnerabilities, particularly within the SNMP and DHCP subsystems, requiring continuous patching and strict access controls to mitigate exploitation risks.

PROFILE
CategorynetworkingWhat they doCisco IOS and IOS XE are operating systems for Cisco networking hardware, providing routing, switching, and network management capabilities.Founded1984 Websitehttps://www.cisco.com ↗
SECURITY POSTURE

The security posture is characterized by a high frequency of high-severity remote code execution (RCE) vulnerabilities across multiple subsystems including SNMP, DHCP, QoS, and UDP processing, indicating systemic issues in input validation and memory management within the codebase.

Notable failures
  • CVE-2025-20352: SNMP stack-based buffer overflow RCE
  • CVE-2017-6742: SNMP authenticated remote RCE
  • CVE-2017-3881: CMP unauthenticated remote RCE
Patterns: repeated unpatched edge-device RCEs; systemic SNMP subsystem vulnerabilities; unauthenticated remote RCEs across multiple protocol handlers
FAILURE HISTORY · 18
DATEEVENTSEVSUMMARY
2022-03-25 CVE-2017-3881 high Cisco IOS and IOS XE suffered a remote code execution vulnerability in the Cluster Management Protocol allowing unauthenticated attackers to execute elevated code or reload devices.
2022-03-03 CVE-2018-0151 high An unauthenticated remote attacker could execute arbitrary code with elevated privileges in Cisco IOS and IOS XE QoS subsystems.
2021-11-03 CVE-2018-0171 high Cisco IOS and IOS XE Smart Install allows unauthenticated remote attackers to execute code, causing device reloads, DoS, or full compromise.
2022-03-03 CVE-2017-6739 high An authenticated remote attacker could execute code or reload a Cisco IOS/XE device via an SNMP vulnerability.
2022-03-03 CVE-2017-6743 high An authenticated remote attacker could execute code via the SNMP subsystem in Cisco IOS and IOS XE software.
2022-03-03 CVE-2017-6740 high An authenticated remote attacker could execute code on Cisco IOS and IOS XE devices via an SNMP vulnerability.
2022-03-03 CVE-2017-6738 high Cisco IOS and IOS XE SNMP subsystems allowed authenticated remote attackers to execute arbitrary code via CVE-2017-6738.
2022-03-03 CVE-2017-6736 high Cisco IOS and IOS XE software contained an SNMP remote code execution vulnerability allowing authenticated attackers to execute arbitrary code remotely.
2022-03-03 CVE-2017-12240 high An unauthenticated remote attacker could execute arbitrary code and gain full control of Cisco IOS and IOS XE systems via a DHCP relay subsystem vulnerability.
2022-03-03 CVE-2017-6737 high Cisco IOS and IOS XE software suffered a remote code execution vulnerability in its SNMP subsystem that allowed authenticated attackers to execute arbitrary code remotely.
2025-09-29 CVE-2025-20352 high Cisco IOS and IOS XE SNMP RCE DoS
2023-10-10 CVE-2023-20109 high Cisco IOS and IOS XE Group Encrypted Transport VPN out-of-bounds write vulnerability allows remote code execution.
2023-04-19 CVE-2017-6742 high Cisco IOS and IOS XE SNMP RCE vulnerability exploited in the wild
2022-03-03 CVE-2017-6627 high Cisco IOS and IOS XE software suffered a high-severity unauthenticated remote denial-of-service vulnerability in UDP packet processing that was actively exploited in the wild.
2022-03-03 CVE-2018-0173 high Cisco IOS and IOS XE Software suffered an unpatched improper input validation vulnerability in DHCPv4 packet handling that caused denial-of-service and was actively exploited in the wild.
2022-03-03 CVE-2018-0172 high Cisco IOS and IOS XE Software suffered a DoS vulnerability in DHCP option 82 encapsulation that was actively exploited in the wild.
2022-03-03 CVE-2017-12237 high Cisco IOS and IOS XE software suffered a DoS vulnerability in its IKEv2 module that allowed unauthenticated remote attackers to crash devices, highlighting systemic unpatched flaws in foundational networking gear.
2022-03-03 CVE-2017-6663 high An unauthenticated adjacent attacker could force Cisco IOS/IOS XE autonomic nodes to reload, causing a denial-of-service.
DOSSIER SOURCES
Open questions: Current patching SLA for IOS XE vulnerabilities · Specific mitigation configurations for SNMP RCEs in IOS XE
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-16 04:42:39.461819+00:00