cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 15 of 30
CVE-2013-5479P4HIGHCVSS 7.8v12.2v15.0+3 more2013-09-27
CVE-2013-5479 [HIGH] CWE-20 CVE-2013-5479: The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows re The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCtn53730.
nvd
CVE-2013-5477P4HIGHCVSS 7.8v12.2v15.0+3 more2013-09-27
CVE-2013-5477 [HIGH] CWE-20 CVE-2013-5477: The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denial of service (interface queue wedge) via bursty network traffic, aka Bug ID CSCub67465.
nvd
CVE-2013-5478P4HIGHCVSS 7.8v15.0v15.1+2 more2013-09-27
CVE-2013-5478 [HIGH] CWE-20 CVE-2013-5478: Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote a Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via crafted UDP RSVP packets, aka Bug ID CSCuf17023.
nvd
CVE-2011-3282P4HIGHCVSS 7.8v12.2\(33\)srev12.2\(33\)sre0a+6 more2011-10-03
CVE-2011-3282 [HIGH] CVE-2011-3282: Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device reload) via an ICMPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCtj30155.
nvd
CVE-2011-0939P4HIGHCVSS 7.8v12.4v15.0+1 more2011-10-03
CVE-2011-0939 [HIGH] CVE-2011-0939: Unspecified vulnerability in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows Unspecified vulnerability in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (device reload) via a crafted SIP message, aka Bug ID CSCth03022.
nvd
CVE-2010-2827P4HIGHCVSS 7.8v15.1\(2\)t2010-08-16
CVE-2010-2827 [HIGH] CWE-20 CVE-2010-2827: Cisco IOS 15.1(2)T allows remote attackers to cause a denial of service (resource consumption and TC Cisco IOS 15.1(2)T allows remote attackers to cause a denial of service (resource consumption and TCP outage) via spoofed TCP packets, related to embryonic TCP connections that remain in the SYN_RCVD or SYN_SENT state, aka Bug ID CSCti18193.
nvd
CVE-2011-2072P4HIGHCVSS 7.8v12.4v15.0+1 more2011-10-03
CVE-2011-2072 [HIGH] CWE-399 CVE-2011-2072: Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified C Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su4, 8.x before 8.5(1)su2, and 8.6 before 8.6(1) allows remote attackers to cause a denial of service (memory consumption and device reload or process failure) via a malformed SIP message, aka Bug IDs
nvd
CVE-2010-0585P4HIGHCVSS 7.8v12.1ydv12.1ye+91 more2010-03-25
CVE-2010-0585 [HIGH] CVE-2010-0585: Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unifie Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug ID CSCsz48614, the "SCCP Packet Processing Denial of Service Vulnerab
nvd
CVE-2024-20465P3MEDIUMCVSS 5.8v15.2\(8\)e2v15.2\(8\)e3+6 more2024-09-25
CVE-2024-20465 [MEDIUM] CWE-284 CVE-2024-20465: A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL. This vulnerability is due to the incorrect handling of IPv4 ACLs on switched virtual interfaces when an administrator e
nvd
CVE-2005-1058P3HIGHCVSS 7.5v12.2tv12.3+1 more2005-05-02
CVE-2005-1058 [HIGH] CVE-2005-1058: Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authenticati Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.
nvd
CVE-2009-0630P4HIGHCVSS 7.1v12.0v12.0da+308 more2009-03-27
CVE-2009-0630 [HIGH] CVE-2009-0630: The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transpo The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and Media Encryption; (4) Blocks Extensible Exchange Protocol (BEEP); (5) Network Admission Control HTTP Authentication Proxy; (6) Per-user URL Redirect for EAPoUDP, Dot1x, and MAC Authentication Bypass; (7)
nvd
CVE-2018-0475P4HIGHCVSS 7.4v15.0\(2.0.0\)2018-10-05
CVE-2018-0475 [HIGH] CWE-20 CVE-2018-0475: A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE A vulnerability in the implementation of the cluster feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation when handling Cluster Management Protocol (CMP) messages. An attacker coul
nvd
CVE-2018-0282P3MEDIUMCVSS 6.8v15.2\(2\)e42019-01-10
CVE-2018-0282 [MEDIUM] CWE-371 CVE-2018-0282: A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticat A vulnerability in the TCP socket code of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a state condition between the socket state and the transmission control block (TCB) state. While this vulnerability potentially affects all TCP applications, the only
nvd
CVE-2007-0917P4MEDIUMCVSS 6.4v12.3tv12.3xq+23 more2007-02-14
CVE-2007-0917 [MEDIUM] CVE-2007-0917: The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.
nvd
CVE-2013-5552P4MEDIUMCVSS 6.4≤ 12.4\(24\)mdb14v12.4\(24\)md+23 more2013-11-13
CVE-2013-5552 [MEDIUM] CWE-264 CVE-2013-5552: Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly imple Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass intended access restrictions via a crafted series of packets, aka Bug ID CSCug90143.
nvd
CVE-2025-20181P4MEDIUMCVSS 6.8v15.0\(1\)exv15.0\(1\)ey+210 more2025-05-07
CVE-2025-20181 [MEDIUM] CWE-347 CVE-2025-20181: A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Sw A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust. This vulnerability is due to missing si
nvd
CVE-2020-3204P4MEDIUMCVSS 6.7v12.2\(6\)i1v12.2\(33\)sre+956 more2020-06-03
CVE-2020-3204 [MEDIUM] CWE-20 CVE-2020-3204: A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS X A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient input validation of data passed to t
nvd
CVE-2002-1357P4CRITICALCVSS 10.0v12.0sv12.0st+6 more2002-12-23
CVE-2002-1357 [CRITICAL] CWE-119 CVE-2002-1357: Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect len Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
nvd
CVE-2009-5038P4HIGHCVSS 7.8fixed in 15.0\(1\)xa2011-01-07
CVE-2009-5038 [HIGH] CWE-20 CVE-2009-5038: Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a certain IRC server, related to a "corrupted magic value," aka Bug ID CSCso05336.
nvd
CVE-2008-3798P4HIGHCVSS 7.8v12.4v12.4mr2008-09-26
CVE-2008-3798 [HIGH] CVE-2008-3798: Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, pro Cisco IOS 12.4 allows remote attackers to cause a denial of service (device crash) via a normal, properly formed SSL packet that occurs during termination of an SSL session.
nvd