Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 13 of 30
CVE-2010-2829P3HIGHCVSS 7.8v12.1tv12.1xi+167 more2010-09-23
CVE-2010-2829 [HIGH] CVE-2010-2829: Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 throug
Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 2.5.x before 2.5.2 and 2.6.x before 2.6.1, allows remote attackers to cause a denial of service (traceback and device reload) via crafted H.323 packets, aka Bug ID CSCtd33567.
nvd
CVE-2010-2831P3HIGHCVSS 7.8v12.1v12.1t+189 more2010-09-23
CVE-2010-2831 [HIGH] CVE-2010-2831: Unspecified vulnerability in the NAT for SIP implementation in Cisco IOS 12.1 through 12.4 and 15.0
Unspecified vulnerability in the NAT for SIP implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1 allows remote attackers to cause a denial of service (device reload) via transit traffic on UDP port 5060, aka Bug ID CSCtf17624.
nvd
CVE-2010-2833P3HIGHCVSS 7.8v12.1v12.1t+189 more2010-09-23
CVE-2010-2833 [HIGH] CVE-2010-2833: Unspecified vulnerability in the NAT for H.225.0 implementation in Cisco IOS 12.1 through 12.4 and 1
Unspecified vulnerability in the NAT for H.225.0 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1 allows remote attackers to cause a denial of service (device reload) via transit traffic, aka Bug ID CSCtd86472.
nvd
CVE-2010-2832P3HIGHCVSS 7.8v12.1v12.1t+189 more2010-09-23
CVE-2010-2832 [HIGH] CVE-2010-2832: Unspecified vulnerability in the NAT for H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.
Unspecified vulnerability in the NAT for H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1 allows remote attackers to cause a denial of service (device reload) via transit traffic, aka Bug ID CSCtf91428.
nvd
CVE-2010-2828P3HIGHCVSS 7.8v12.1tv12.1xi+167 more2010-09-23
CVE-2010-2828 [HIGH] CVE-2010-2828: Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 throug
Unspecified vulnerability in the H.323 implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 2.5.x before 2.5.2 and 2.6.x before 2.6.1, allows remote attackers to cause a denial of service (device reload) via crafted H.323 packets, aka Bug ID CSCtc73759.
nvd
CVE-2009-2868P3HIGHCVSS 7.8v12.2exv12.2ira+38 more2009-09-28
CVE-2009-2868 [HIGH] CVE-2009-2868: Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is e
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.
nvd
CVE-2013-1147P3HIGHCVSS 7.8v12.3v12.4+4 more2013-03-28
CVE-2013-1147 [HIGH] CWE-119 CVE-2013-1147: The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, wh
The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, when one-step port-23 translation or a Telnet-to-PAD ruleset is configured, does not properly validate TCP connection information, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a PT resource, aka B
nvd
CVE-2016-6391P3HIGHCVSS 7.5v12.2\(44\)exv12.2\(44\)ex1+83 more2016-10-05
CVE-2016-6391 [HIGH] CWE-399 CVE-2016-6391: Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-p
Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036.
nvd
CVE-2011-3280P3HIGHCVSS 7.5v12.1v12.1e+185 more2011-10-03
CVE-2011-3280 [HIGH] CWE-399 CVE-2011-3280: Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS
Memory leak in the NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted SIP packets to UDP port 5060, aka Bug ID CSCtj04672.
nvd
CVE-2016-1347P3HIGHCVSS 7.5v15.1\(4\)gc2v15.1\(4\)m6+31 more2016-03-24
CVE-2016-1347 [HIGH] CWE-399 CVE-2016-1347: The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allo
The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.
nvd
CVE-2007-4292P3CRITICALCVSS 9.3v12.0v12.1+3 more2007-08-09
CVE-2007-4292 [CRITICAL] CVE-2007-4292: Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of ser
Multiple memory leaks in Cisco IOS 12.0 through 12.4 allow remote attackers to cause a denial of service (device crash) via a malformed SIP packet, aka (1) CSCsf11855, (2) CSCeb21064, (3) CSCse40276, (4) CSCse68355, (5) CSCsf30058, (6) CSCsb24007, and (7) CSCsc60249.
nvd
CVE-2011-4661P3HIGHCVSS 7.5fixed in 15.2\(1\)tvbefore 15.2(1)T2020-02-12
CVE-2011-4661 [HIGH] CWE-772 CVE-2011-4661: A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PRO
A memory leak vulnerability exists in Cisco IOS before 15.2(1)T due to a memory leak in the HTTP PROXY Server process (aka CSCtu52820), when configured with Cisco ISR Web Security with Cisco ScanSafe and User Authenticaiton NTLM configured.
nvd
CVE-2017-3849P3HIGHCVSS 7.4v15.2\(3\)ev15.2\(3\)e1+75 more2017-03-21
CVE-2017-3849 [HIGH] CWE-20 CVE-2017-3849: A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Soft
A vulnerability in the Autonomic Networking Infrastructure (ANI) registrar feature of Cisco IOS Software (possibly 15.2 through 15.6) and Cisco IOS XE Software (possibly 3.7 through 3.18, and 16) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certa
nvd
CVE-2018-15373P3HIGHCVSS 7.4v15.5\(3\)s3.162018-10-05
CVE-2018-15373 [HIGH] CWE-399 CVE-2018-15373: A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Softwar
A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper memory handling by the affected software when t
nvd
CVE-2020-3409P3HIGHCVSS 7.4v15.2\(7\)ev16.11.1a2020-09-24
CVE-2020-3409 [HIGH] CWE-20 CVE-2020-3409: A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow
A vulnerability in the PROFINET feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to crash and reload, resulting in a denial of service (DoS) condition on the device. The vulnerability is due to insufficient processing logic for crafted PROFINET packets that are sent to an
nvd
CVE-2014-2146P3MEDIUMCVSS 6.5≤ 15.4\(1\)t12016-09-22
CVE-2014-2146 [MEDIUM] CWE-20 CVE-2014-2146: The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, po
The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoofed traffic that matches one of these sessions, aka Bug IDs CSCun94946 and CSCun96847.
nvd
CVE-2021-34703P3MEDIUMCVSS 6.5≤ 16.12.32021-09-23
CVE-2021-34703 [MEDIUM] CWE-456 CVE-2021-34703: A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and
A vulnerability in the Link Layer Discovery Protocol (LLDP) message parser of Cisco IOS Software and Cisco IOS XE Software could allow an attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper initialization of a buffer. An attacker could exploit this vulnerability
nvd
CVE-2012-5032P3MEDIUMCVSS 6.4≤ 15.1\(1\)sy2v15.1+2 more2014-04-23
CVE-2012-5032 [MEDIUM] CWE-287 CVE-2012-5032: The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3
The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug I
nvd
CVE-2020-3210P3MEDIUMCVSS 6.7v12.2\(60\)ez16v15.0\(2\)sg11a+4 more2020-06-03
CVE-2020-3210 [MEDIUM] CWE-77 CVE-2020-3210: A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated
A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated, local attacker to execute arbitrary shell commands on the Virtual Device Server (VDS) of an affected device. The attacker must have v
nvd
CVE-2010-4671P4HIGHCVSS 7.8fixed in 15.0\(1\)xa52011-01-07
CVE-2010-4671 [HIGH] CWE-400 CVE-2010-4671: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS before 15.0(1)XA5 allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, as demonstrated by the flood_router6 program in the thc-ipv6 package, aka Bug ID CS
nvd