cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 10 of 30
CVE-2012-3949P3HIGHCVSS 7.8v12.2v12.2b+206 more2012-09-27
CVE-2012-3949 [HIGH] CWE-20 CVE-2012-3949: The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a cra
nvd
CVE-2015-0586P3HIGHCVSS 7.8≤ 15.3\(100\)m2015-01-28
CVE-2015-0586 [HIGH] CWE-399 CVE-2015-0586: The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and earlier on Cisco 2900 Integrated Services Router (aka Cisco Internet Router) devices allows remote attackers to cause a denial of service (NBAR process hang) via IPv4 packets, aka Bug ID CSCuo73682.
nvd
CVE-2016-6392P3HIGHCVSS 7.5v12.2\(33\)cxv12.2\(33\)cy+431 more2016-10-05
CVE-2016-6392 [HIGH] CWE-399 CVE-2016-6392: Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a de Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.
nvd
CVE-2009-2863P3HIGHCVSS 7.1v12.0xkv12.0xr+134 more2009-09-28
CVE-2009-2863 [HIGH] CWE-287 CVE-2009-2863: Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows re Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.
nvd
CVE-2021-34714P3HIGHCVSS 7.4≤ 8.4\(3.115\)≤ 7.0\(3\)i7\(9\)+3 more2021-09-23
CVE-2021-34714 [HIGH] CWE-20 CVE-2021-34714: A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IO A vulnerability in the Unidirectional Link Detection (UDLD) feature of Cisco FXOS Software, Cisco IOS Software, Cisco IOS XE Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. This vulnerability is due to improper input validation of the UDLD packets. An att
nvd
CVE-2024-20276P3HIGHCVSS 7.4v15.5\(1\)sy5v15.5\(1\)sy6+12 more2024-03-27
CVE-2024-20276 [HIGH] CWE-248 CVE-2024-20276: A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthe A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of process-switched traffic. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A
nvd
CVE-2024-20312P3HIGHCVSS 7.4v15.0\(1\)exv15.1\(1\)sy+850 more2024-03-27
CVE-2024-20312 [HIGH] CWE-476 CVE-2024-20312: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Soft A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An atta
nvd
CVE-2015-6385P3HIGHCVSS 7.2v15.5\(2\)sv15.5\(3\)s2015-12-01
CVE-2015-6385 [HIGH] CWE-20 CVE-2015-6385: The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943.
nvd
CVE-2007-4263P3HIGHCVSS 8.5v12.22007-08-08
CVE-2007-4263 [HIGH] CVE-2007-4263: Unspecified vulnerability in the server side of the Secure Copy (SCP) implementation in Cisco 12.2-b Unspecified vulnerability in the server side of the Secure Copy (SCP) implementation in Cisco 12.2-based IOS allows remote authenticated users to read, write or overwrite any file on the device's filesystem via unknown vectors.
nvd
CVE-2009-2051P3HIGHCVSS 7.8≥ 12.2, ≤ 12.4≥ 15.0, ≤ 15.12009-08-27
CVE-2009-2051 [HIGH] CVE-2009-2051: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message t
nvd
CVE-2008-3808P3HIGHCVSS 7.8v12.0v12.0da+250 more2008-09-26
CVE-2008-3808 [HIGH] CVE-2008-3808: Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial o Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted Protocol Independent Multicast (PIM) packet.
nvd
CVE-2014-3327P3HIGHCVSS 7.8v12.2v15.0+3 more2014-08-11
CVE-2014-3327 [HIGH] CWE-20 CVE-2014-3327: The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4 The EnergyWise module in Cisco IOS 12.2, 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.2.xXO, 3.3.xSG, 3.4.xSG, and 3.5.xE before 3.5.3E allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 packet, aka Bug ID CSCup52101.
nvd
CVE-2012-0386P3HIGHCVSS 7.8v12.2v12.4+3 more2012-03-29
CVE-2012-0386 [HIGH] CWE-310 CVE-2012-0386: The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6. The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a denial of service (device reload) via a crafted username in a reverse SSH login attempt, aka Bug ID CSCtr49064.
nvd
CVE-2010-0578P3HIGHCVSS 7.8v12.2sbv12.2sca+59 more2010-03-25
CVE-2010-0578 [HIGH] CWE-310 CVE-2010-0578: The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allo The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service (device reload) via a malformed IKE packet, aka Bug ID CSCtb13491.
nvd
CVE-2009-2866P3HIGHCVSS 7.8v12.2bv12.2bx+70 more2009-09-28
CVE-2009-2866 [HIGH] CVE-2009-2866: Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial o Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104.
nvd
CVE-2009-2869P3HIGHCVSS 7.8v12.2xnav12.2xnb+8 more2009-09-28
CVE-2009-2869 [HIGH] CVE-2009-2869: Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, an Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948.
nvd
CVE-2012-4623P3HIGHCVSS 7.8v12.3v12.3\(1a\)+291 more2012-09-27
CVE-2012-4623 [HIGH] CWE-20 CVE-2012-4623: The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6. The DHCPv6 server in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x, 3.1.xS before 3.1.4S, 3.1.xSG and 3.2.xSG before 3.2.5SG, 3.2.xS, 3.2.xXO, 3.3.xS, and 3.3.xSG before 3.3.1SG allows remote attackers to cause a denial of service (device reload) via a malformed DHCPv6 packet, aka Bug ID CSCto57723.
nvd
CVE-2012-4618P3HIGHCVSS 7.8v12.2v12.4+4 more2012-09-27
CVE-2012-4618 [HIGH] CWE-399 CVE-2012-4618: The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows The SIP ALG feature in the NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtn76183.
nvd
CVE-2016-6385P3HIGHCVSS 7.5v12.2\(35\)exv12.2\(35\)ex1+156 more2016-10-05
CVE-2016-6385 [HIGH] CWE-399 CVE-2016-6385: Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and I Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.
nvd
CVE-2015-0636P3HIGHCVSS 7.8v12.2\(33\)ird1v12.2\(33\)ire3+21 more2015-03-26
CVE-2015-0636 [HIGH] CWE-20 CVE-2015-0636: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15 The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine, aka Bug ID CSCup62293.
nvd