Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 18 of 30
CVE-2007-5651P4HIGHCVSS 7.1v12.1v12.2+5 more2007-10-23
CVE-2007-5651 [HIGH] CVE-2007-5651: Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IO
Unspecified vulnerability in the Extensible Authentication Protocol (EAP) implementation in Cisco IOS 12.3 and 12.4 on Cisco Access Points and 1310 Wireless Bridges (Wireless EAP devices), IOS 12.1 and 12.2 on Cisco switches (Wired EAP devices), and CatOS 6.x through 8.x on Cisco switches allows remote attackers to cause a denial of service (device reload) via
nvd
CVE-2006-4775P4HIGHCVSS 7.8v12.1\(19\)2006-09-14
CVE-2006-4775 [HIGH] CWE-399 CVE-2006-4775: The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to
The VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) and CatOS allows remote attackers to cause a denial of service by sending a VTP update with a revision value of 0x7FFFFFFF, which is incremented to 0x80000000 and is interpreted as a negative number in a signed context.
nvd
CVE-2019-12672P4MEDIUMCVSS 6.8v16.9.12019-09-25
CVE-2019-12672 [MEDIUM] CWE-59 CVE-2019-12672: A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attac
A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical access to an affected device to execute arbitrary code on the underlying operating system (OS) with root privileges. The vulnerability is due to insufficient file location validation. An attacker could exploit this vulnerability by pl
nvd
CVE-2016-6423P4MEDIUMCVSS 6.5v15.5\(3\)m2016-10-05
CVE-2016-6423 [MEDIUM] CWE-399 CVE-2016-6423: The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 s
The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.
nvd
CVE-2019-1649P4MEDIUMCVSS 6.7fixed in 15.6\(3\)m7≥ 15.7, ≤ 15.7\(3\)m5+5 more2019-05-13
CVE-2019-1649 [MEDIUM] CWE-284 CVE-2019-1649: A vulnerability in the logic that handles access control to one of the hardware components in Cisco'
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vuln
nvd
CVE-2008-1153P4HIGHCVSS 7.1v12.1v12.22008-03-27
CVE-2008-1153 [HIGH] CVE-2008-1153: Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows r
Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.
nvd
CVE-2017-3850P4MEDIUMCVSS 5.9v15.2\(3\)ev15.2\(3\)e1+60 more2017-03-21
CVE-2017-3850 [MEDIUM] CWE-20 CVE-2017-3850: A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4
A vulnerability in the Autonomic Networking Infrastructure (ANI) feature of Cisco IOS Software (15.4 through 15.6) and Cisco IOS XE Software (3.7 through 3.18, and 16) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to incomplete input validation on certain crafted packets. An attac
nvd
CVE-2007-0648P4HIGHCVSS 7.8v12.3\(14\)tv12.3\(14\)t2+51 more2007-02-01
CVE-2007-0648 [HIGH] CVE-2007-0648: Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session I
Cisco IOS after 12.3(14)T, 12.3(8)YC1, 12.3(8)YG, and 12.4, with voice support and without Session Initiated Protocol (SIP) configured, allows remote attackers to cause a denial of service (crash) by sending a crafted packet to port 5060/UDP.
nvd
CVE-2004-0079P4HIGHCVSS 7.5v12.1\(11\)ev12.1\(11b\)e+8 more2004-11-23
CVE-2004-0079 [HIGH] CWE-476 CVE-2004-0079: The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
nvd
CVE-2010-0579P4HIGHCVSS 7.8v12.3jkv12.3t+41 more2010-03-25
CVE-2010-0579 [HIGH] CVE-2010-0579: The SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of servi
The SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device reload) via a malformed SIP message, aka Bug ID CSCtb93416, the "SIP Message Handling Denial of Service Vulnerability."
nvd
CVE-2019-1757P4MEDIUMCVSS 5.9v2.3v12.2\(6\)i1+129 more2019-03-28
CVE-2019-1757 [MEDIUM] CWE-295 CVE-2019-1757: A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an
A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by
nvd
CVE-2017-12228P4MEDIUMCVSS 5.9v12.4\(25e\)jao3av12.4\(25e\)jao20s+434 more2017-09-29
CVE-2017-12228 [MEDIUM] CWE-20 CVE-2017-12228: A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Ci
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An atta
nvd
CVE-2011-4667P4MEDIUMCVSS 5.9v12.2\(33\)sxiv12.2\(33\)sxj+3 more2017-09-25
CVE-2011-4667 [MEDIUM] CWE-310 CVE-2011-4667: The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco
The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS 9000 18/4-Port Multiservice Module, and Cisco MDS 9000 Storage Services Node module before 5.2(6), and Cisco IOS in Cisco VPN Services Port Adaptor for Catalyst 6500 12.2(33)SXI, and 12.2(33)SXJ when IP
nvd
CVE-2001-0929P4HIGHCVSS 7.5v11.2pv11.3t+7 more2001-11-28
CVE-2001-0929 [HIGH] CVE-2001-0929: Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated S
Cisco IOS Firewall Feature set, aka Context Based Access Control (CBAC) or Cisco Secure Integrated Software, for IOS 11.2P through 12.2T does not properly check the IP protocol type, which could allow remote attackers to bypass access control lists.
nvd
CVE-2013-1145P4HIGHCVSS 7.8v12.2v12.4+2 more2013-03-28
CVE-2013-1145 [HIGH] CWE-399 CVE-2013-1145: Memory leak in Cisco IOS 12.2, 12.4, 15.0, and 15.1, when Zone-Based Policy Firewall SIP application
Memory leak in Cisco IOS 12.2, 12.4, 15.0, and 15.1, when Zone-Based Policy Firewall SIP application layer gateway inspection is enabled, allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed SIP messages, aka Bug ID CSCtl99174.
nvd
CVE-2014-2124P4HIGHCVSS 7.1≤ 15.1\(2\)sy32014-03-21
CVE-2014-2124 [HIGH] CWE-399 CVE-2014-2124: Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 d
Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of service (device crash) via crafted multicast packets, aka Bug ID CSCuf60783.
nvd
CVE-2013-5481P4HIGHCVSS 7.1v12.2v15.0+3 more2013-09-27
CVE-2013-5481 [HIGH] CWE-20 CVE-2013-5481: The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote att
The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 packets, aka Bug ID CSCtq14817.
nvd
CVE-2013-5472P4HIGHCVSS 7.1v12.0v12.1+5 more2013-09-27
CVE-2013-5472 [HIGH] CWE-20 CVE-2013-5472: The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through
The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.
nvd
CVE-2015-0638P4HIGHCVSS 7.1v12.2\(33\)ird1v12.2\(33\)ire3+29 more2015-03-26
CVE-2015-0638 [HIGH] CWE-20 CVE-2015-0638: Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attack
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.
nvd
CVE-2014-2107P4HIGHCVSS 7.1v12.2v15.0+4 more2014-03-27
CVE-2014-2107 [HIGH] CWE-20 CVE-2014-2107: Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE a
Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attackers to cause a denial of service (route switch processor outage) via crafted IP packets, aka Bug ID CSCug84789.
nvd