cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 11 of 30
CVE-2012-4619P3HIGHCVSS 7.8v12.2v12.4+4 more2012-09-27
CVE-2012-4619 [HIGH] CWE-399 CVE-2012-4619: The NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cau The NAT implementation in Cisco IOS 12.2, 12.4, and 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via transit IP packets, aka Bug ID CSCtr46123.
nvd
CVE-2010-2835P3HIGHCVSS 7.8v12.1v12.1t+189 more2010-09-23
CVE-2010-2835 [HIGH] CVE-2010-2835: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7.0(2a)su3, 7.1su before 7.1(3b)su2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allow remote attackers to cause a denial of service (device reload or voice-services ou
nvd
CVE-2011-0945P3HIGHCVSS 7.8v12.1v12.1t+189 more2011-10-03
CVE-2011-0945 [HIGH] CWE-399 CVE-2011-0945: Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 th Memory leak in the Data-link switching (aka DLSw) feature in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xS before 3.1.3S and 3.2.xS before 3.2.1S, when implemented over Fast Sequence Transport (FST), allows remote attackers to cause a denial of service (memory consumption and device reload or hang) via a crafted IP protocol 91 pac
nvd
CVE-2011-3277P3HIGHCVSS 7.8v12.1v12.1e+185 more2011-10-03
CVE-2011-3277 [HIGH] CVE-2011-3277: Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted H.323 packets to TCP port 1720, aka Bug ID CSCth11006.
nvd
CVE-2011-3278P3HIGHCVSS 7.8v12.1v12.1e+185 more2011-10-03
CVE-2011-3278 [HIGH] CVE-2011-3278: Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCti48483.
nvd
CVE-2011-3276P3HIGHCVSS 7.8v12.1v12.1e+185 more2011-10-03
CVE-2011-3276 [HIGH] CVE-2011-3276: Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through Unspecified vulnerability in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) by sending crafted SIP packets to TCP port 5060, aka Bug ID CSCso02147.
nvd
CVE-2009-0637P3HIGHCVSS 7.1v12.2v12.2b+184 more2009-03-27
CVE-2009-0637 [HIGH] CWE-264 CVE-2009-0637: The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enfor The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command.
nvd
CVE-2016-1478P3HIGHCVSS 7.5v15.5\(3\)s3v15.6\(1\)s2+2 more2016-08-08
CVE-2016-1478 [HIGH] CWE-20 CVE-2016-1478: Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packe Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.
nvd
CVE-2011-2058P3HIGHCVSS 7.5≥ 12.2, < 12.2\(33\)sxi72011-10-22
CVE-2011-2058 [HIGH] CWE-20 CVE-2011-2058: The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an extern The cat6000-dot1x component in Cisco IOS 12.2 before 12.2(33)SXI7 does not properly handle an external loop between a pair of dot1x enabled ports, which allows remote attackers to cause a denial of service (traffic storm) via unspecified vectors that trigger many unicast EAPoL Protocol Data Units (PDUs), aka Bug ID CSCtq36336.
nvd
CVE-2011-1640P3HIGHCVSS 7.5≥ 12.2, < 12.2\(33\)sxj12011-10-22
CVE-2011-1640 [HIGH] CWE-400 CVE-2011-1640: The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large The ethernet-lldp component in Cisco IOS 12.2 before 12.2(33)SXJ1 does not properly support a large number of LLDP Management Address (MA) TLVs, which allows remote attackers to cause a denial of service (device crash) via crafted LLDPDUs, aka Bug ID CSCtj22354.
nvd
CVE-2016-6409P3HIGHCVSS 7.5v15.6\(1\)t2016-09-24
CVE-2016-6409 [HIGH] CWE-399 CVE-2016-6409: The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is ena The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.
nvd
CVE-2007-4295P3MEDIUMCVSS 6.8v12.0v12.1+3 more2007-08-09
CVE-2007-4295 [MEDIUM] CVE-2007-4295: Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to execute arbitrar Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80749.
nvd
CVE-2007-4285P3CRITICALCVSS 9.0v12.0v12.1+2 more2007-08-09
CVE-2007-4285 [CRITICAL] CVE-2007-4285: Unspecified vulnerability in Cisco IOS and Cisco IOS XR 12.x up to 12.3, including some versions bef Unspecified vulnerability in Cisco IOS and Cisco IOS XR 12.x up to 12.3, including some versions before 12.3(15) and 12.3(14)T, allows remote attackers to obtain sensitive information (partial packet contents) or cause a denial of service (router or component crash) via crafted IPv6 packets with a Type 0 routing header.
nvd
CVE-2018-15369P3MEDIUMCVSS 6.8v15.6\(1.9\)t2018-10-05
CVE-2018-15369 [MEDIUM] CWE-20 CVE-2018-15369: A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software coul A vulnerability in the TACACS+ client subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper handling of crafted TACACS+ response packets by the affected software. An attacker
nvd
CVE-2011-4012P3CRITICALCVSS 9.3v12.0v15.0+1 more2012-05-02
CVE-2011-4012 [CRITICAL] CVE-2011-4012: Cisco IOS 12.0, 15.0, and 15.1, when a Policy Feature Card 3C (PFC3C) is used, does not create a fra Cisco IOS 12.0, 15.0, and 15.1, when a Policy Feature Card 3C (PFC3C) is used, does not create a fragment entry during processing of an ICMPv6 ACL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtj90091.
nvd
CVE-2011-0348P3MEDIUMCVSS 6.4v12.4\(11\)mdv12.4\(15\)md+5 more2011-01-28
CVE-2011-0348 [MEDIUM] CWE-264 CVE-2011-0348: Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4 Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on the Cisco Content Services Gateway Second Generation (aka CSG2) allows remote attackers to bypass intended access restrictions and intended billing restrictions by sending HTTP traffic to a restricted des
nvd
CVE-2016-6410P3MEDIUMCVSS 6.5v15.5\(2\)t2016-09-24
CVE-2016-6410 [MEDIUM] CWE-20 CVE-2016-6410: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.
nvd
CVE-2008-1152P3HIGHCVSS 7.8v12.0v12.2yd+3 more2008-03-27
CVE-2008-1152 [HIGH] CWE-399 CVE-2008-1152: The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to c The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.
nvd
CVE-2018-0484P3MEDIUMCVSS 6.5v16.6.2v16.6.42019-01-10
CVE-2018-0484 [MEDIUM] CWE-284 CVE-2018-0484: A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE A vulnerability in the access control logic of the Secure Shell (SSH) server of Cisco IOS and IOS XE Software may allow connections sourced from a virtual routing and forwarding (VRF) instance despite the absence of the vrf-also keyword in the access-class configuration. The vulnerability is due to a missing check in the SSH server. An attacker could
nvd
CVE-2008-3813P3HIGHCVSS 7.8v12.2sev12.2sg+7 more2008-09-26
CVE-2008-3813 [HIGH] CVE-2008-3813: Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when the L2TP mgmt daemon process is enabled, Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when the L2TP mgmt daemon process is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted L2TP packet.
nvd