Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 28 SEP 2026

Cisco · AUTOMATIC DISCOVERY

Cisco IOS XE Lifecycle policy

Cisco IOS XE is tracked by BlackTree as an operating system or system software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.

Product overview

Cisco IOS XE is tracked by BlackTree as an operating system or system software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Application and workload execution
  • Hardware, networking and storage management
  • Security updates and platform maintenance

Typical use

Used on endpoints, servers, appliances, virtual machines or cloud instances.

Deployment

Installed on physical or virtual systems, or delivered as an appliance or cloud image.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductCisco IOS XE
ReleaseLifecycle policy
Start or releaseNot extracted
Lifecycle boundaryContinuous or not dated in the source
Date precisionUnknown

Known exploited vulnerabilities

Catalogue updated 1 Oct 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2023-20273Added 23 Oct 2023

Cisco IOS XE Web UI Command Injection Vulnerability

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

Cisco · Cisco IOS XE Web UIRansomware use: Unknown

CISA entry
CVE-2023-20198Added 16 Oct 2023

Cisco IOS XE Web UI Privilege Escalation Vulnerability

Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a remote, unauthenticated attacker to create an account with privilege level 15 access. The attacker can then use that account to gain control of the affected device.

Cisco · IOS XE Web UIRansomware use: Unknown

CISA entry
CVE-2017-3881Added 25 Mar 2022

Cisco IOS and IOS XE Remote Code Execution Vulnerability

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.

Cisco · IOS and IOS XERansomware use: Unknown

CISA entry
CVE-2018-0175Added 3 Mar 2022

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

Cisco · IOS, XR, and XE SoftwareRansomware use: Unknown

CISA entry
CVE-2018-0174Added 3 Mar 2022

Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

Cisco · IOS XE SoftwareRansomware use: Unknown

CISA entry
CVE-2018-0173Added 3 Mar 2022

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).

Cisco · IOS and IOS XE SoftwareRansomware use: Unknown

CISA entry

Showing the 6 most recently added of 17 product-family matches.

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYManual

Cisco IOS XE official lifecycle source

Types of software releases | Cisco IOS XE Software Support | Optional rebuilds | End-of-Sale and End-of-Life guideline definition | Cisco Catalyst SD-WAN Software release model | Cisco Catalyst SD-WAN Software Support | Optional rebuilds

Publisher identity used by product-specific official-source collectors.

First collected 12 Sep 2026 · Last collected 28 Sep 2026 · Review state accepted

Open official vendor source