FAIL › dossier
IOS, XR, and XE Software
PRODUCT· dossier confidence 20%
Cisco's IOS XR/XE operating systems have a documented history of high-severity remote code execution vulnerabilities in core network protocols like LLDP and SCP, exploitable by unauthenticated adjacent attackers. The failure history reveals recurring issues with input validation and memory safety in protocol implementations, requiring strict patching and network segmentation to mitigate risk.
PROFILE
CategorynetworkingWhat they doCisco IOS XR, IOS XE, and IOS XE Software are operating systems for Cisco networking hardware, providing routing, switching, and network management capabilities.
Websitehttps://www.cisco.com ↗
SECURITY POSTURE
The security posture is characterized by high-severity remote code execution vulnerabilities in core protocol implementations (LLDP, SCP) that were exploitable by unauthenticated adjacent attackers, indicating systemic issues in input validation and memory safety within the software stack.
Notable failures
- CVE-2018-0175: Format string RCE in LLDP
- CVE-2018-0167: Buffer overflow RCE in LLDP
- CSCwr59895: SCP Server DoS vulnerability
Patterns: unauthenticated adjacent RCEs in protocol daemons; format string and buffer overflow vulnerabilities in legacy code paths; operational defects in secure copy and management protocols
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-03-03 | CVE-2018-0175 | high | A format string vulnerability in Cisco IOS XR/IOS XE LLDP allowed unauthenticated adjacent attackers to execute arbitrary code with elevated privileges. |
| 2022-03-03 | CVE-2018-0167 | high | An unauthenticated adjacent attacker could exploit a buffer overflow in Cisco IOS XR LLDP to execute arbitrary code or cause a DoS. |
DOSSIER SOURCES
- Twitter, Inc. - Wikipedia · en.wikipedia.org
- Ios Xe CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- Iphone Os CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- BugZero | Cisco BugID CSCwr59895 - Cisco IOS XE Software Secure Copy ... · www.findbugzero.com
Open questions: Are there additional CVEs in the internal failure history not listed? · What is the current patching SLA for these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-17 03:49:45.911860+00:00