Cisco iOS vulnerabilities
582 known vulnerabilities affecting cisco/ios.
Total CVEs
582
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH328MEDIUM212LOW11
Vulnerabilities
Page 16 of 30
CVE-2009-2870P4HIGHCVSS 7.8v12.3ykv12.3ys+17 more2009-09-28
CVE-2009-2870 [HIGH] CVE-2009-2870: Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feat
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880.
nvd
CVE-2010-0582P4HIGHCVSS 7.8v12.1xuv12.1yd+99 more2010-03-25
CVE-2010-0582 [HIGH] CVE-2010-0582: Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial o
Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (interface queue wedge) via malformed H.323 packets, aka Bug ID CSCta19962.
nvd
CVE-2014-2112P4HIGHCVSS 7.8v15.1v15.2+2 more2014-03-27
CVE-2014-2112 [HIGH] CWE-20 CVE-2014-2112: The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a d
The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357.
nvd
CVE-2012-0383P4HIGHCVSS 7.8v12.4v15.0+1 more2012-03-29
CVE-2012-0383 [HIGH] CWE-399 CVE-2012-0383: Memory leak in the NAT feature in Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a
Memory leak in the NAT feature in Cisco IOS 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (memory consumption, and device hang or reload) via SIP packets that require translation, related to a "memory starvation vulnerability," aka Bug ID CSCti35326.
nvd
CVE-2013-5553P4HIGHCVSS 7.8v15.12013-11-08
CVE-2013-5553 [HIGH] CWE-399 CVE-2013-5553: Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of
Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383.
nvd
CVE-2013-5476P4HIGHCVSS 7.8v15.1v15.22013-09-27
CVE-2013-5476 [HIGH] CWE-20 CVE-2013-5476: The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP
The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attackers to cause a denial of service (device reload or hang) via crafted IPv4 HTTP traffic, aka Bug ID CSCtx56174.
nvd
CVE-2011-0946P4HIGHCVSS 7.8≥ 12.1, ≤ 12.4≥ 15.0, ≤ 15.12011-10-03
CVE-2011-0946 [HIGH] CVE-2011-0946: The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, all
The NAT implementation in Cisco IOS 12.1 through 12.4 and 15.0 through 15.1, and IOS XE 3.1.xSG, allows remote attackers to cause a denial of service (device reload or hang) via malformed NetMeeting Directory (aka Internet Locator Service or ILS) LDAP traffic, aka Bug ID CSCtd10712.
nvd
CVE-2011-3273P4HIGHCVSS 7.8v15.0v15.0m+9 more2011-10-03
CVE-2011-3273 [HIGH] CWE-399 CVE-2011-3273: Memory leak in Cisco IOS 15.0 through 15.1, when IPS or Zone-Based Firewall (aka ZBFW) is configured
Memory leak in Cisco IOS 15.0 through 15.1, when IPS or Zone-Based Firewall (aka ZBFW) is configured, allows remote attackers to cause a denial of service (memory consumption or device crash) via vectors that trigger many session creation flows, aka Bug ID CSCti79848.
nvd
CVE-2012-4621P4HIGHCVSS 7.8v15.0v15.0\(1\)se+2 more2012-09-27
CVE-2012-4621 [HIGH] CWE-399 CVE-2012-4621: The Device Sensor feature in Cisco IOS 15.0 through 15.2 allows remote attackers to cause a denial o
The Device Sensor feature in Cisco IOS 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via a DHCP packet, aka Bug ID CSCty96049.
nvd
CVE-2013-5474P4HIGHCVSS 7.8v12.2v12.3+5 more2013-09-27
CVE-2013-5474 [HIGH] CWE-362 CVE-2013-5474: Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 t
Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers to cause a denial of service (device reload or hang) via fragmented IPv6 packets, aka Bug ID CSCud64812.
nvd
CVE-2013-5480P4HIGHCVSS 7.8v12.2v15.0+3 more2013-09-27
CVE-2013-5480 [HIGH] CWE-20 CVE-2013-5480: The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows re
The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCuf28733.
nvd
CVE-2011-1624P4HIGHCVSS 7.8v12.2\(58\)se2011-08-18
CVE-2011-1624 [HIGH] CWE-399 CVE-2011-1624: Cisco IOS 12.2(58)SE, when a login banner is configured, allows remote attackers to cause a denial o
Cisco IOS 12.2(58)SE, when a login banner is configured, allows remote attackers to cause a denial of service (device reload) by establishing two SSH2 sessions, aka Bug ID CSCto62631.
nvd
CVE-2005-1058P3HIGHCVSS 7.5v12.2tv12.3+1 more2005-05-02
CVE-2005-1058 [HIGH] CVE-2005-1058: Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authenticati
Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.
nvd
CVE-2003-1109P4HIGHCVSS 7.5v12.2\(1\)xav12.2\(1\)xd+55 more2003-12-31
CVE-2003-1109 [HIGH] CVE-2003-1109: The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone m
The Session Initiation Protocol (SIP) implementation in multiple Cisco products including IP Phone models 7940 and 7960, IOS versions in the 12.2 train, and Secure PIX 5.2.9 to 6.2.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
nvd
CVE-2015-0608P4HIGHCVSS 7.1≤ 15.4\(2\)t3v15.4\(1\)t+8 more2015-02-12
CVE-2015-0608 [HIGH] CWE-362 CVE-2015-0608: Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisc
Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCul4
nvd
CVE-2007-0917P4MEDIUMCVSS 6.4v12.3tv12.3xq+23 more2007-02-14
CVE-2007-0917 [MEDIUM] CVE-2007-0917: The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers
The Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XE to 12.3T allows remote attackers to bypass IPS signatures that use regular expressions via fragmented packets.
nvd
CVE-2004-0244P4MEDIUMCVSS 4.7PoCv12.1ev12.2sy+1 more2004-11-23
CVE-2004-0244 [MEDIUM] CWE-20 CVE-2004-0244: Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWA
Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inconsistent length values with that packet.
nvd
CVE-2025-20181P4MEDIUMCVSS 6.8v15.0\(1\)exv15.0\(1\)ey+210 more2025-05-07
CVE-2025-20181 [MEDIUM] CWE-347 CVE-2025-20181: A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Sw
A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with physical access to the device to execute persistent code at boot time and break the chain of trust.
This vulnerability is due to missing si
nvd
CVE-2007-0648P4HIGHCVSS 7.8v12.3\(14\)tv12.3\(14\)t2+51 more2007-02-01
CVE-2007-0648 [HIGH] CVE-2007-0648: Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session I
Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.
nvd
CVE-2018-15375P4MEDIUMCVSS 6.7v15.5\(2.21\)tv15.6\(3\)m2018-10-05
CVE-2018-15375 [MEDIUM] CWE-123 CVE-2018-15375: A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial
A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The vulnerability is due to the presence of certain test commands that were intended
nvd