Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
36
actively exploited
Public exploits
28
Exploited in wild
36
Severity breakdown
CRITICAL32HIGH327MEDIUM211LOW11
Vulnerabilities
Page 2 of 30
CVE-2025-20175HIGHCVSS 7.7v12.2\(33\)sxi4v12.2\(33\)sxi4a+1786 more2025-02-05
CVE-2025-20175 [HIGH] CWE-805 CVE-2025-20175: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
cvelistv5nvd
CVE-2025-20169HIGHCVSS 7.7v12.2\(1\)v12.2\(1\)dx+5896 more2025-02-05
CVE-2025-20169 [HIGH] CWE-805 CVE-2025-20169: A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affect
cvelistv5nvd
CVE-2024-20433HIGHCVSS 7.5v12.0\(24\)sv12.0\(24\)s1+4072 more2024-09-25
CVE-2024-20433 [HIGH] CWE-121 CVE-2024-20433: A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco
A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to a buffer overflow when processing crafted RSVP packets. An
cvelistv5nvd
CVE-2024-20465MEDIUMCVSS 5.8v15.2\(8\)e2v15.2\(8\)e3+6 more2024-09-25
CVE-2024-20465 [MEDIUM] CWE-284 CVE-2024-20465: A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco
A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a configured ACL.
This vulnerability is due to the incorrect handling of IPv4 ACLs on switched virtual interfaces when an administrator e
cvelistv5nvd
CVE-2024-20414MEDIUMCVSS 6.5v15.2\(6\)e2v15.2\(6\)e2a+58 more2024-09-25
CVE-2024-20414 [MEDIUM] CWE-285 CVE-2024-20414: A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through the web UI.
This vulnerability is due to incorrectly accepting configuration changes through the HTTP GET method. An attacker could e
cvelistv5nvd
CVE-2024-20307HIGHCVSS 7.5v15.1\(2\)sg8v15.1\(2\)sy8+292 more2024-03-27
CVE-2024-20307 [HIGH] CWE-121 CVE-2024-20307: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabili
cvelistv5nvd
CVE-2024-20276HIGHCVSS 7.4v15.5\(1\)sy5v15.5\(1\)sy6+12 more2024-03-27
CVE-2024-20276 [HIGH] CWE-248 CVE-2024-20276: A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthe
A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent attacker to cause an affected device to reload unexpectedly.
This vulnerability is due to improper handling of process-switched traffic. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A
cvelistv5nvd
CVE-2024-20312HIGHCVSS 7.4v15.0\(1\)exv15.1\(1\)sy+850 more2024-03-27
CVE-2024-20312 [HIGH] CWE-476 CVE-2024-20312: A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Soft
A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insufficient input validation when parsing an ingress IS-IS packet. An atta
cvelistv5nvd
CVE-2024-20311HIGHCVSS 7.5v15.1\(1\)syv15.1\(1\)sy1+778 more2024-03-27
CVE-2024-20311 [HIGH] CWE-674 CVE-2024-20311: A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to
cvelistv5nvd
CVE-2024-20308HIGHCVSS 7.5v12.4\(22\)mdv12.4\(22\)md1+1260 more2024-03-27
CVE-2024-20308 [HIGH] CWE-787 CVE-2024-20308: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabil
cvelistv5nvd
CVE-2023-20186CRITICALCVSS 9.1v12.2\(58\)exv12.2\(58\)ey+1227 more2023-09-27
CVE-2023-20186 [CRITICAL] CWE-285 CVE-2023-20186: A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Soft
A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP).
This vulnerability is due to incorrect
cvelistv5nvd
CVE-2023-20109MEDIUMCVSS 6.6KEVv12.4\(22\)mdv12.4\(22\)md1+1346 more2023-09-27
CVE-2023-20109 [MEDIUM] CWE-787 CVE-2023-20109: A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software a
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash.
This vulnerability is due to i
cvelistv5nvd
CVE-2023-20080HIGHCVSS 7.5v12.2\(6\)i1v15.1\(2\)sg+485 more2023-03-23
CVE-2023-20080 [HIGH] CWE-129 CVE-2023-20080: A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS X
A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries. An attacker could exploit this vulnerability by sending crafted DHCPv6 me
nvd
CVE-2023-20081MEDIUMCVSS 5.9v17.8.12023-03-23
CVE-2023-20081 [MEDIUM] CWE-122 CVE-2023-20081: A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) S
A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu
nvd
CVE-2022-20920HIGHCVSS 7.7v12.2\(6\)i1v12.2\(58\)ex+1175 more2022-10-10
CVE-2022-20920 [HIGH] CWE-755 CVE-2022-20920: A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allo
A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affecte
nvd
CVE-2022-20726HIGHCVSS 7.5v15.2\(5\)e1v15.2\(5\)e2c+54 more2022-04-15
CVE-2022-20726 [HIGH] CWE-22 CVE-2022-20726: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS) at
nvd
CVE-2022-20697HIGHCVSS 8.6v15.1\(3\)svr1v15.1\(3\)svr2+24 more2022-04-15
CVE-2022-20697 [HIGH] CWE-691 CVE-2022-20697: A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could
A vulnerability in the web services interface of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper resource management in the HTTP server code. An attacker could exploit this vulnerability by sending a large number of HTTP reques
nvd
CVE-2022-20761MEDIUMCVSS 6.5v15.4\(1\)cgv15.4\(2\)cg+84 more2022-04-15
CVE-2022-20761 [MEDIUM] CWE-248 CVE-2022-20761: A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Ser
A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an unauthenticated, adjacent attacker to cause a denial of service condition on an affected device. This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit
nvd
CVE-2022-20727MEDIUMCVSS 6.7v15.2\(5\)e1v15.2\(6\)e0a+67 more2022-04-15
CVE-2022-20727 [MEDIUM] CWE-22 CVE-2022-20727: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2022-20724MEDIUMCVSS 5.3v15.2\(5\)e1v15.2\(5\)e2c+68 more2022-04-15
CVE-2022-20724 [MEDIUM] CWE-22 CVE-2022-20724: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd