Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 2 of 30
CVE-2018-0158P2HIGHCVSS 8.6KEVv15.5\(3\)s1.1v15.5\(3\)s1.2+8 more2018-03-28
CVE-2018-0158 [HIGH] CWE-20 CVE-2018-0158: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisc
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An atta
nvd
CVE-2017-12235P2HIGHCVSS 7.5KEV≥ 12.2, ≤ 15.62017-09-29
CVE-2017-12235 [HIGH] CWE-20 CVE-2017-12235: A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP)
A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request pa
nvd
CVE-2017-12234P2HIGHCVSS 7.5KEV≥ 12.4, ≤ 15.62017-09-29
CVE-2017-12234 [HIGH] CWE-20 CVE-2017-12234: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Ci
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an a
nvd
CVE-2017-12233P2HIGHCVSS 7.5KEV≥ 12.4, ≤ 15.62017-09-29
CVE-2017-12233 [HIGH] CWE-20 CVE-2017-12233: Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Ci
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an a
nvd
CVE-2018-0159P2HIGHCVSS 7.5KEVv15.3\(3\)s2018-03-28
CVE-2018-0159 [HIGH] CWE-20 CVE-2018-0159: A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Ci
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of specific IKEv1 packets. A
nvd
CVE-2023-20109P2MEDIUMCVSS 6.6KEVv12.4\(22\)mdv12.4\(22\)md1+1346 more2023-09-27
CVE-2023-20109 [MEDIUM] CWE-787 CVE-2023-20109: A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software a
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash.
This vulnerability is due to i
nvd
CVE-2017-12319P2MEDIUMCVSS 5.9KEVv15.4\(1\)s2018-03-27
CVE-2017-12319 [MEDIUM] CWE-20 CVE-2017-12319: A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN)
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vul
nvd
CVE-2017-12237P2HIGHCVSS 7.5KEV≥ 15.0, ≤ 15.62017-09-29
CVE-2017-12237 [HIGH] CWE-399 CVE-2017-12237: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an
nvd
CVE-2017-12231P2HIGHCVSS 7.5KEV≥ 12.4, ≤ 15.62017-09-29
CVE-2017-12231 [HIGH] CWE-399 CVE-2017-12231: A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IO
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Stat
nvd
CVE-2017-6627P2HIGHCVSS 7.5KEVv15.1\(2\)gcv15.1\(2\)gc1+33 more2017-09-07
CVE-2017-6627 [HIGH] CWE-399 CVE-2017-6627: A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application
nvd
CVE-2017-12232P2MEDIUMCVSS 6.5KEV≥ 15.0, ≤ 15.62017-09-29
CVE-2017-12232 [MEDIUM] CWE-399 CVE-2017-12232: A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Etherne
nvd
CVE-2017-6663P2MEDIUMCVSS 6.5KEVv15.2\(3\)ev15.2\(3\)e1+115 more2017-08-07
CVE-2017-6663 [MEDIUM] CVE-2017-6663: A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
nvd
CVE-2017-12238P2MEDIUMCVSS 6.5KEV≥ 15.0, ≤ 15.42017-09-29
CVE-2017-12238 [MEDIUM] CWE-399 CVE-2017-12238: A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Ci
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or C6800-16P10G-XL type line card to crash, resulting in a denial of service (DoS) condition. The vulnerability is due to a memory management i
nvd
CVE-2018-0180P2MEDIUMCVSS 5.9KEVv15.3\(00.00.19\)syv15.4\(01\)ia001.100+5 more2018-03-28
CVE-2018-0180 [MEDIUM] CWE-399 CVE-2018-0180: Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)
nvd
CVE-2018-0179P2MEDIUMCVSS 5.9KEVv15.3\(00.00.19\)syv15.4\(01\)ia001.100+5 more2018-03-28
CVE-2018-0179 [MEDIUM] CWE-399 CVE-2018-0179: Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)
nvd
CVE-2018-0161P2MEDIUMCVSS 6.3KEVv15.2\(5\)e2018-03-28
CVE-2018-0161 [MEDIUM] CWE-399 CVE-2018-0161: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software run
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occ
nvd
CVE-2004-1464P2MEDIUMCVSS 5.9KEV≤ 12.2\(15\)zj32004-12-31
CVE-2004-1464 [MEDIUM] CWE-400 CVE-2004-1464: Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (vi
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.
nvd
CVE-2001-0537P2CRITICALCVSS 9.3ExploitedPoCv11.3v11.3aa+89 more2001-07-21
CVE-2001-0537 [CRITICAL] CWE-287 CVE-2001-0537: HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitra
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.
nvd
CVE-2025-20363P1CRITICALCVSS 9.0Exploited≥ 12.2\(15\)b, ≤ 15.9\(3\)m11v12.2(15)B+2004 more2025-09-25
CVE-2025-20363 [CRITICAL] CWE-122 CVE-2025-20363: A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS,
nvd
CVE-2000-0984P2MEDIUMCVSS 5.0ExploitedPoCv12.0tv12.0w5+22 more2000-12-19
CVE-2000-0984 [MEDIUM] CVE-2000-0984: The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (cras
The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.
nvd