Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
36
actively exploited
Public exploits
28
Exploited in wild
36
Severity breakdown
CRITICAL32HIGH327MEDIUM211LOW11

Vulnerabilities

Page 1 of 30
CVE-2026-20125HIGHCVSS 7.7v12.2(33)CYv12.2(33)CY1+941 more2026-03-25
CVE-2026-20125 [HIGH] CWE-228 CVE-2026-20125: A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3 A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this
cvelistv5nvd
CVE-2026-20012HIGHCVSS 8.6v15.2(1)Sv15.2(2)S+551 more2026-03-25
CVE-2026-20012 [HIGH] CWE-401 CVE-2026-20012: A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) co
cvelistv5nvd
CVE-2025-20363CRITICALCVSS 9.0≥ 12.2\(15\)b, ≤ 15.9\(3\)m11v12.2(15)B+2004 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
cvelistv5nvd
CVE-2025-20327HIGHCVSS 7.7v15.2(6)E2v15.2(7)E+27 more2025-09-24
CVE-2025-20327 [HIGH] CWE-1287 CVE-2025-20327: A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker wi A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an HTTP request. A successful exploit
cvelistv5nvd
CVE-2025-20160HIGHCVSS 8.1v15.2(6)E1v15.2(4)E6+122 more2025-09-24
CVE-2025-20160 [HIGH] CWE-287 CVE-2025-20160: A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine-in-the-mi
cvelistv5nvd
CVE-2025-20352HIGHCVSS 7.7KEVv12.2\(33\)sxiv12.2\(33\)sxi1+1450 more2025-09-24
CVE-2025-20352 [HIGH] CWE-121 CVE-2025-20352: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS,
cvelistv5nvd
CVE-2025-20149MEDIUMCVSS 6.5v15.2(1)Sv15.2(2)S+737 more2025-09-24
CVE-2025-20149 [MEDIUM] CWE-120 CVE-2025-20149: A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authentica A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by usi
cvelistv5nvd
CVE-2025-20239HIGHCVSS 8.6v15.2(4)Ev15.2(4)E1+236 more2025-08-14
CVE-2025-20239 [HIGH] CWE-401 CVE-2025-20239: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This vul
cvelistv5nvd
CVE-2025-20225MEDIUMCVSS 5.8v15.1(2)Tv15.1(1)T4+418 more2025-08-14
CVE-2025-20225 [MEDIUM] CWE-401 CVE-2025-20225: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This v
cvelistv5nvd
CVE-2025-20164HIGHCVSS 8.3v15.0(2)SE8v15.0(2)EA+73 more2025-05-07
CVE-2025-20164 [HIGH] CWE-862 CVE-2025-20164: A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software co A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due to insufficient validation of authorizations for authenticated users. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affec
cvelistv5nvd
CVE-2025-20154HIGHCVSS 8.6≤ 15.9\(3\)m112025-05-07
CVE-2025-20154 [HIGH] CWE-20 CVE-2025-20154: A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Softw A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a denial of service (DoS) condition. For Cisco IOS XR Software, this vulnerability could cause the ipsla_ippm_server proces
nvd
CVE-2025-20137MEDIUMCVSS 4.7v15.2\(5a\)ev15.2\(5b\)e+68 more2025-05-07
CVE-2025-20137 [MEDIUM] CWE-284 CVE-2025-20137: A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running o A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the use of both an IPv4 ACL and a dynamic ACL of IP Source Guard on the same inte
cvelistv5nvd
CVE-2025-20196MEDIUMCVSS 5.3vN/A2025-05-07
CVE-2025-20196 [MEDIUM] CWE-307 CVE-2025-20196: A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of HTTP reques
cvelistv5nvd
CVE-2025-20181MEDIUMCVSS 6.8v15.0\(1\)exv15.0\(1\)ey+210 more2025-05-07
CVE-2025-20181 [MEDIUM] CWE-347 CVE-2025-20181: A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Sw A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to missing si
cvelistv5nvd
CVE-2025-20172HIGHCVSS 7.7v12.2\(33\)srev12.2\(33\)sre0a+1354 more2025-02-05
CVE-2025-20172 [HIGH] CWE-248 CVE-2025-20172: A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted S
cvelistv5nvd
CVE-2025-20171HIGHCVSS 7.7v12.2\(33\)cxv12.2\(33\)cy+2252 more2025-02-05
CVE-2025-20171 [HIGH] CWE-248 CVE-2025-20171: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
cvelistv5nvd
CVE-2025-20174HIGHCVSS 7.7v15.2\(1\)syv15.2\(1\)sy0a+436 more2025-02-05
CVE-2025-20174 [HIGH] CWE-805 CVE-2025-20174: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
cvelistv5nvd
CVE-2025-20176HIGHCVSS 7.7v15.0\(1\)syv15.0\(1\)sy1+1020 more2025-02-05
CVE-2025-20176 [HIGH] CWE-248 CVE-2025-20176: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
cvelistv5nvd
CVE-2025-20170HIGHCVSS 7.7v12.2\(1\)v12.2\(1\)dx+5896 more2025-02-05
CVE-2025-20170 [HIGH] CWE-805 CVE-2025-20170: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
cvelistv5nvd
CVE-2025-20173HIGHCVSS 7.7v12.2\(33\)srev12.2\(33\)sre0a+1920 more2025-02-05
CVE-2025-20173 [HIGH] CWE-248 CVE-2025-20173: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
cvelistv5nvd
1 / 30Next →
Cisco iOS vulnerabilities | cvebase