Cisco searched for IOS XR bugs and found so many it rolled them into an update release
What happened
Cisco published an advisory after an internal review that flagged several critical vulnerabilities in IOS XR and some Nexus 9000 Series switches. The advisory highlights remote-code and improper-access-control risks and recommends mitigations like infrastructure ACLs while fixes are validated. Procurement should demand patch timelines and require mitigation attestations from suppliers; watch for expanded affected model lists
Why the category manager should care
Treat this as an operational supplier risk: require mitigations now and force patch-and-verify timelines into supplier commitments
Key facts
- Multiple critical-rated vulnerabilities affecting IOS XR and Nexus devices
- Advisory highlights remote-code and improper certificate/authentication issues
- Vendor mitigation recommendation: use infrastructure ACLs to restrict management traffic