Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 12 of 30
CVE-2007-2688P3HIGHCVSS 7.8v10.0v11.1cc+10 more2007-05-16
CVE-2007-2688 [HIGH] CVE-2007-2688: The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly ha
The Cisco Intrusion Prevention System (IPS) and IOS with Firewall/IPS Feature Set do not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
nvd
CVE-2014-3358P3HIGHCVSS 7.8v15.0v15.1+2 more2014-09-25
CVE-2014-3358 [HIGH] CWE-78 CVE-2014-3358: Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO befor
Memory leak in Cisco IOS 15.0, 15.1, 15.2, and 15.4 and IOS XE 3.3.xSE before 3.3.2SE, 3.3.xXO before 3.3.1XO, 3.5.xE before 3.5.2E, and 3.11.xS before 3.11.1S allows remote attackers to cause a denial of service (memory consumption, and interface queue wedge or device reload) via malformed mDNS packets, aka Bug ID CSCuj58950.
nvd
CVE-2014-3359P3HIGHCVSS 7.8v15.1v15.2+2 more2014-09-25
CVE-2014-3359 [HIGH] CWE-399 CVE-2014-3359: Memory leak in Cisco IOS 15.1 through 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.
Memory leak in Cisco IOS 15.1 through 15.4 and IOS XE 3.4.xS, 3.5.xS, 3.6.xS, and 3.7.xS before 3.7.6S; 3.8.xS, 3.9.xS, and 3.10.xS before 3.10.1S; and 3.11.xS before 3.12S allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed DHCPv6 packets, aka Bug ID CSCum90081.
nvd
CVE-2012-4620P3HIGHCVSS 7.8v12.2v15.0+3 more2012-09-27
CVE-2012-4620 [HIGH] CWE-399 CVE-2012-4620: Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists,
Cisco IOS 12.2 and 15.0 through 15.2 on Cisco 10000 series routers, when a tunnel interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via tunneled (1) GRE/IP, (2) IPIP, or (3) IPv6 in IPv4 packets, aka Bug ID CSCts66808.
nvd
CVE-2011-3279P3HIGHCVSS 7.8≥ 12.1, ≤ 12.4≥ 15.0, ≤ 15.12011-10-03
CVE-2011-3279 [HIGH] CVE-2011-3279: The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and
The provider-edge MPLS NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload) via a malformed SIP packet to UDP port 5060, aka Bug ID CSCti98219.
nvd
CVE-2010-0584P3HIGHCVSS 7.8v12.4gcv12.4md+24 more2010-03-25
CVE-2010-0584 [HIGH] CVE-2010-0584: Unspecified vulnerability in Cisco IOS 12.4, when NAT SCCP fragmentation support is enabled, allows
Unspecified vulnerability in Cisco IOS 12.4, when NAT SCCP fragmentation support is enabled, allows remote attackers to cause a denial of service (device reload) via crafted Skinny Client Control Protocol (SCCP) packets, aka Bug ID CSCsy09250.
nvd
CVE-2009-2867P3HIGHCVSS 7.8v12.2xnav12.2xnb+6 more2009-09-28
CVE-2009-2867 [HIGH] CVE-2009-2867: Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA
Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691.
nvd
CVE-2014-2109P3HIGHCVSS 7.8v12.2v12.3+6 more2014-03-27
CVE-2014-2109 [HIGH] CWE-20 CVE-2014-2109: The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows
The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494.
nvd
CVE-2014-2108P3HIGHCVSS 7.8v12.2v15.0+4 more2014-03-27
CVE-2014-2108 [HIGH] CWE-20 CVE-2014-2108: Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 b
Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a denial of service (device reload) via a malformed IKEv2 packet, aka Bug ID CSCui88426.
nvd
CVE-2013-1148P3HIGHCVSS 7.8v15.22013-03-28
CVE-2013-1148 [HIGH] CWE-119 CVE-2013-1148: The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15
The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S allows remote attackers to cause a denial of service (device reload) via crafted (1) IPv4 or (2) IPv6 IP SLA packets on UDP port 1167, aka Bug ID CSCuc72594.
nvd
CVE-2015-0649P3HIGHCVSS 7.8v12.2\(33\)ird1v12.2\(33\)ire3+43 more2015-03-26
CVE-2015-0649 [HIGH] CWE-20 CVE-2015-0649: Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (dev
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.
nvd
CVE-2015-0647P3HIGHCVSS 7.8v12.2\(33\)ird1v12.2\(33\)ire3+57 more2015-03-26
CVE-2015-0647 [HIGH] CWE-20 CVE-2015-0647: Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (dev
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) UDP packets, aka Bug ID CSCum98371.
nvd
CVE-2011-2064P3HIGHCVSS 7.8v12.4\(24\)md1v12.4\(24\)md2+4 more2011-07-11
CVE-2011-2064 [HIGH] CWE-399 CVE-2011-2064: Cisco IOS 12.4MDA before 12.4(24)MDA5 on the Cisco Content Services Gateway - Second Generation (CSG
Cisco IOS 12.4MDA before 12.4(24)MDA5 on the Cisco Content Services Gateway - Second Generation (CSG2) allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets, aka Bug ID CSCtl79577.
nvd
CVE-2009-0631P3HIGHCVSS 7.8v12.0v12.0da+308 more2009-03-27
CVE-2009-0631 [HIGH] CVE-2009-0631: Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when configured with (1) IP Service Level
Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when configured with (1) IP Service Level Agreements (SLAs) Responder, (2) Session Initiation Protocol (SIP), (3) H.323 Annex E Call Signaling Transport, or (4) Media Gateway Control Protocol (MGCP) allows remote attackers to cause a denial of service (blocked input queue on the inbound interface) via a c
nvd
CVE-2015-0637P3HIGHCVSS 7.8v12.2\(33\)ird1v12.2\(33\)ire3+26 more2015-03-26
CVE-2015-0637 [HIGH] CWE-20 CVE-2015-0637: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka Bug ID CSCup62315.
nvd
CVE-2013-5475P3HIGHCVSS 7.8v12.2v12.3+5 more2013-09-27
CVE-2013-5475 [HIGH] CWE-20 CVE-2013-5475: Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attacke
Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.
nvd
CVE-2012-1350P3HIGHCVSS 7.8v12.3v12.3\(1a\)+300 more2012-08-06
CVE-2012-1350 [HIGH] CVE-2012-1350: Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of servic
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.
nvd
CVE-2015-0592P3HIGHCVSS 7.8≤ 15.4\(2\)t3v15.4\(1\)t+8 more2015-02-12
CVE-2015-0592 [HIGH] CWE-399 CVE-2015-0592: The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to
The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers incorrect kernel-timer handling, aka Bug ID CSCuh25672.
nvd
CVE-2011-3270P3HIGHCVSS 7.8v12.2\(28\)sbv12.2\(28\)sb1+47 more2011-10-03
CVE-2011-3270 [HIGH] CVE-2011-3270: Unspecified vulnerability in Cisco IOS 12.2SB before 12.2(33)SB10 and 15.0S before 15.0(1)S3a on Cis
Unspecified vulnerability in Cisco IOS 12.2SB before 12.2(33)SB10 and 15.0S before 15.0(1)S3a on Cisco 10000 series routers allows remote attackers to cause a denial of service (device reload) via a sequence of crafted ICMP packets, aka Bug ID CSCtk62453.
nvd
CVE-2010-2834P3HIGHCVSS 7.8v12.1v12.1t+189 more2010-09-23
CVE-2010-2834 [HIGH] CVE-2010-2834: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)SU1, 7.x before 7.1(5), and 8.0 before 8.0(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via crafted SIP registration traffic ov
nvd