Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 17 of 30
CVE-2018-15376P4MEDIUMCVSS 6.7v15.5\(2.21\)tv15.6\(3\)m2018-10-05
CVE-2018-15376 [MEDIUM] CWE-123 CVE-2018-15376: A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial
A vulnerability in the embedded test subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers could allow an authenticated, local attacker to write arbitrary values to arbitrary locations in the memory space of an affected device. The vulnerability is due to the presence of certain test commands that were intended
nvd
CVE-2018-0163P4MEDIUMCVSS 6.5v15.4\(3\)m6v15.4\(3\)m6a+31 more2018-03-28
CVE-2018-0163 [MEDIUM] CWE-287 CVE-2018-0163: A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software cou
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access a
nvd
CVE-2010-4683P4HIGHCVSS 7.8fixed in 15.0\(1\)xa52011-01-07
CVE-2010-4683 [HIGH] CWE-772 CVE-2010-4683: Memory leak in Cisco IOS before 15.0(1)XA5 might allow remote attackers to cause a denial of service
Memory leak in Cisco IOS before 15.0(1)XA5 might allow remote attackers to cause a denial of service (memory consumption) by sending a crafted SIP REGISTER message over UDP, aka Bug ID CSCtg41733.
nvd
CVE-2011-2578P4HIGHCVSS 7.8v15.1v15.22012-05-02
CVE-2011-2578 [HIGH] CWE-399 CVE-2011-2578: Memory leak in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory
Memory leak in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (memory consumption) via malformed SIP packets on a NAT interface, aka Bug ID CSCts12366.
nvd
CVE-2008-2739P4HIGHCVSS 7.8v12.3tv12.3xl+21 more2008-09-26
CVE-2008-2739 [HIGH] CVE-2008-2739: The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4
The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerability than CVE-2008-1447.
nvd
CVE-2012-0387P4HIGHCVSS 7.8v12.4v15.0+2 more2012-03-29
CVE-2012-0387 [HIGH] CWE-399 CVE-2012-0387: Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0
Memory leak in the HTTP Inspection Engine feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted transit HTTP traffic, aka Bug ID CSCtq36153.
nvd
CVE-2008-3811P4HIGHCVSS 7.8v12.4mdv12.4mr+15 more2008-09-26
CVE-2008-3811 [HIGH] CVE-2008-3811: Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabl
Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka Cisco Bug ID CSCsi17020, a different vulnerability than CVE-2008-3810.
nvd
CVE-2008-3810P4HIGHCVSS 7.8v12.4mdv12.4mr+15 more2008-09-26
CVE-2008-3810 [HIGH] CWE-20 CVE-2008-3810: Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabl
Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka CSCsg22426, a different vulnerability than CVE-2008-3811.
nvd
CVE-2020-3315P4MEDIUMCVSS 5.3v15.2\(7\)ev16.11.2+1 more2020-05-06
CVE-2020-3315 [MEDIUM] CWE-693 CVE-2020-3315: Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could all
Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass the configured file policies on an affected system. The vulnerability is due to errors in how the Snort detection engine handles specific HTTP responses. An attacker could exploit this vulnerability by se
nvd
CVE-2013-1144P4HIGHCVSS 7.8v15.12013-03-28
CVE-2013-1144 [HIGH] CWE-399 CVE-2013-1144: Memory leak in the IKEv1 implementation in Cisco IOS 15.1 allows remote attackers to cause a denial
Memory leak in the IKEv1 implementation in Cisco IOS 15.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified (1) IPv4 or (2) IPv6 IKE packets, aka Bug ID CSCth81055.
nvd
CVE-2011-3281P4HIGHCVSS 7.8v15.0v15.0m+9 more2011-10-03
CVE-2011-3281 [HIGH] CVE-2011-3281: Unspecified vulnerability in Cisco IOS 15.0 through 15.1, in certain HTTP Layer 7 Application Contro
Unspecified vulnerability in Cisco IOS 15.0 through 15.1, in certain HTTP Layer 7 Application Control and Inspection configurations, allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTP packet, aka Bug ID CSCto68554.
nvd
CVE-2011-3275P4HIGHCVSS 7.8v12.4v15.0+1 more2011-10-03
CVE-2011-3275 [HIGH] CWE-399 CVE-2011-3275: Memory leak in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attacke
Memory leak in Cisco IOS 12.4, 15.0, and 15.1, and IOS XE 2.5.x through 3.2.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted SIP message, aka Bug ID CSCti48504.
nvd
CVE-2010-2836P4HIGHCVSS 7.8v12.4v12.4gc+29 more2010-09-23
CVE-2010-2836 [HIGH] CWE-399 CVE-2010-2836: Memory leak in the SSL VPN feature in Cisco IOS 12.4, 15.0, and 15.1, when HTTP port redirection is
Memory leak in the SSL VPN feature in Cisco IOS 12.4, 15.0, and 15.1, when HTTP port redirection is enabled, allows remote attackers to cause a denial of service (memory consumption) by improperly disconnecting SSL sessions, leading to connections that remain in the CLOSE-WAIT state, aka Bug ID CSCtg21685.
nvd
CVE-2025-20225P4MEDIUMCVSS 5.8v15.1(2)Tv15.1(1)T4+418 more2025-08-14
CVE-2025-20225 [MEDIUM] CWE-401 CVE-2025-20225: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition.
This v
nvd
CVE-2012-0388P4HIGHCVSS 7.8v12.4v15.0+2 more2012-03-29
CVE-2012-0388 [HIGH] CWE-399 CVE-2012-0388: Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1
Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553.
nvd
CVE-2013-1146P4HIGHCVSS 7.8v12.2v15.0+4 more2013-03-28
CVE-2013-1146 [HIGH] CWE-119 CVE-2013-1146: The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches
The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in Smart Install packets, aka Bug ID CSCub55790.
nvd
CVE-2011-0941P4HIGHCVSS 7.8v12.4v15.12011-11-01
CVE-2011-0941 [HIGH] CWE-399 CVE-2011-0941: Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)s
Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or device reload) via a malformed SIP message, aka Bug IDs CSCti75128 and CSCtj0917
nvd
CVE-2013-1142P4HIGHCVSS 7.8≥ 12.2, ≤ 12.4≥ 15.0, ≤ 15.22013-03-28
CVE-2013-1142 [HIGH] CWE-362 CVE-2013-1142: Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 all
Race condition in the VRF-aware NAT feature in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 allows remote attackers to cause a denial of service (memory consumption) via IPv4 packets, aka Bug IDs CSCtg47129 and CSCtz96745.
nvd
CVE-2021-34705P4MEDIUMCVSS 5.3v12.3\(7\)xmv12.3\(7\)xr+1437 more2021-09-23
CVE-2021-34705 [MEDIUM] CWE-232 CVE-2021-34705: A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cis
A vulnerability in the Voice Telephony Service Provider (VTSP) service of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass configured destination patterns and dial arbitrary numbers. This vulnerability is due to insufficient validation of dial strings at Foreign Exchange Office (FXO) interfaces.
nvd
CVE-2015-0681P4HIGHCVSS 7.1v12.2\(33\)xn1v12.2\(44\)sq1+7 more2015-07-24
CVE-2015-0681 [HIGH] CWE-399 CVE-2015-0681: The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15
The TFTP server in Cisco IOS 12.2(44)SQ1, 12.2(33)XN1, 12.4(25e)JAM1, 12.4(25e)JAO5m, 12.4(23)JY, 15.0(2)ED1, 15.0(2)EY3, 15.1(3)SVF4a, and 15.2(2)JB1 and IOS XE 2.5.x, 2.6.x, 3.1.xS, 3.2.xS, 3.3.xS, 3.4.xS, and 3.5.xS before 3.6.0S; 3.1.xSG, 3.2.xSG, and 3.3.xSG before 3.4.0SG; 3.2.xSE before 3.3.0SE; 3.2.xXO before 3.3.0XO; 3.2.xSQ; 3.3.xSQ; and 3.4.x
nvd