Cisco Ios vulnerabilities
43 known vulnerabilities affecting cisco/cisco_ios.
Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH24MEDIUM18
Vulnerabilities
Page 2 of 3
CVE-2020-3409P3HIGHCVSS 7.4vn/a2020-09-24
CVE-2020-3409 [HIGH] CWE-20 CVE-2020-3409: A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow
A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to crash and reload, resulting in a denial of service (DoS) condition on the device. The vulnerability is due to insufficient processing logic for crafted PROFINET packets that are sent to an
nvd
CVE-2021-34703P3MEDIUMCVSS 6.5vn/a2021-09-23
CVE-2021-34703 [MEDIUM] CWE-456 CVE-2021-34703: A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and
A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper initialization of a buffer. An attacker could exploit this vulnerability
nvd
CVE-2018-0282P3MEDIUMCVSS 6.8vn/a2019-01-10
CVE-2018-0282 [MEDIUM] CWE-371 CVE-2018-0282: A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticat
A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a state condition between the socket state and the transmission control block (TCB) state. While this vulnerability potentially affects all TCP applications, the only
nvd
CVE-2009-0628P4CRITICALCVSS 9.0v12.3v12.42009-03-27
CVE-2009-0628 [CRITICAL] CWE-200 CVE-2009-0628: Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a
Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL session in an abnormal manner, leading to a Transmission Control Block (TCB) leak.
nvd
CVE-2020-3511P4HIGHCVSS 7.4vn/a2020-09-24
CVE-2020-3511 [HIGH] CWE-20 CVE-2020-3511: A vulnerability in the ISDN subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the ISDN subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the ISDN Q.931 messages are processed. An attacker could exploit t
nvd
CVE-2020-3512P4HIGHCVSS 7.4vn/a2020-09-24
CVE-2020-3512 [HIGH] CWE-388 CVE-2020-3512: A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco I
A vulnerability in the PROFINET handler for Link Layer Discovery Protocol (LLDP) messages of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a crash on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient validation of LLDP messages in the P
nvd
CVE-2021-34705P4MEDIUMCVSS 5.3vn/a2021-09-23
CVE-2021-34705 [MEDIUM] CWE-232 CVE-2021-34705: A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cis
A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces.
nvd
CVE-2008-1153P4HIGHCVSS 7.1v12.3v12.42008-03-27
CVE-2008-1153 [HIGH] CVE-2008-1153: Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows r
Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.
nvd
CVE-2021-1391P4MEDIUMCVSS 6.7vn/a2021-03-24
CVE-2021-1391 [MEDIUM] CWE-489 CVE-2021-1391: A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, loc
A vulnerability in the dragonite debugger of Cisco IOS XE Software could allow an authenticated, local attacker to escalate from privilege level 15 to root privilege. The vulnerability is due to the presence of development testing and verification scripts that remained on the device. An attacker could exploit this vulnerability by bypassing the consen
nvd
CVE-2021-1377P4MEDIUMCVSS 5.8vn/a2021-03-24
CVE-2021-1377 [MEDIUM] CWE-399 CVE-2021-1377: A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS
A vulnerability in Address Resolution Protocol (ARP) management of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent an affected device from resolving ARP entries for legitimate hosts on the connected subnets. This vulnerability exists because ARP entries are mismanaged. An attacker could exploit th
nvd
CVE-2023-20081P4MEDIUMCVSS 5.9vn/a2023-03-23
CVE-2023-20081 [MEDIUM] CWE-122 CVE-2023-20081: A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) S
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu
nvd
CVE-2022-20727P4MEDIUMCVSS 6.7vn/a2022-04-15
CVE-2022-20727 [MEDIUM] CWE-22 CVE-2022-20727: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2022-20677P4MEDIUMCVSS 6.7vn/a2022-04-15
CVE-2022-20677 [MEDIUM] CWE-22 CVE-2022-20677: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2009-0634P4HIGHCVSS 7.1v12.3v12.42009-03-27
CVE-2009-0634 [HIGH] CVE-2009-0634: Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT
Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via an ICMP packet, aka Bug ID CSCso05337.
nvd
CVE-2009-0633P4HIGHCVSS 7.1v12.3v12.42009-03-27
CVE-2009-0633 [HIGH] CVE-2009-0633: Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6
Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.
nvd
CVE-2020-3477P4MEDIUMCVSS 5.5vn/a2020-09-24
CVE-2020-3477 [MEDIUM] CWE-20 CVE-2020-3477: A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an aut
A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific comma
nvd
CVE-2022-20761P4MEDIUMCVSS 6.5vn/a2022-04-15
CVE-2022-20761 [MEDIUM] CWE-248 CVE-2022-20761: A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Ser
A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an unauthenticated, adjacent attacker to cause a denial of service condition on an affected device. This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit
nvd
CVE-2008-1156P4MEDIUMCVSS 5.1v12.3v12.42008-03-27
CVE-2008-1156 [MEDIUM] CWE-16 CVE-2008-1156: Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IO
Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast states on the core routers" via a crafted Multicast Distribution Tree (MDT) Data Join message.
nvd
CVE-2022-20724P4MEDIUMCVSS 5.3vn/a2022-04-15
CVE-2022-20724 [MEDIUM] CWE-22 CVE-2022-20724: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2015-4204P4MEDIUMCVSS 6.8v12.2v12.2\(33\)2015-06-23
CVE-2015-4204 [MEDIUM] CWE-399 CVE-2015-4204: Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices all
Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption or PXF process crash) by sending docsIfMCmtsMib SNMP requests quickly, aka Bug ID CSCue65051.
nvd