cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 20 of 30
CVE-2012-3950P4HIGHCVSS 7.1v12.3v12.3\(1a\)+289 more2012-09-27
CVE-2012-3950 [HIGH] CWE-399 CVE-2012-3950: The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, The Intrusion Prevention System (IPS) feature in Cisco IOS 12.3 through 12.4 and 15.0 through 15.2, in certain configurations of enabled categories and missing signatures, allows remote attackers to cause a denial of service (device reload) via DNS packets, aka Bug ID CSCtw55976.
nvd
CVE-2002-1358P4CRITICALCVSS 10.0v12.0sv12.0st+6 more2002-12-23
CVE-2002-1358 [CRITICAL] CWE-20 CVE-2002-1358: Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
nvd
CVE-2016-1333P4MEDIUMCVSS 6.5v15.5\(3\)mv15.6\(1\)t0a2016-02-17
CVE-2016-1333 [MEDIUM] CWE-399 CVE-2016-1333: Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated u Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.
nvd
CVE-2009-0629P4MEDIUMCVSS 5.4v12.2v12.2b+184 more2009-03-27
CVE-2009-0629 [MEDIUM] CVE-2009-0629: The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel C The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over T
nvd
CVE-2016-6412P4MEDIUMCVSS 6.5v15.6\(1\)t12016-09-24
CVE-2016-6412 [MEDIUM] CWE-20 CVE-2016-6412: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.
nvd
CVE-2019-12670P4MEDIUMCVSS 6.7v16.10.12019-09-25
CVE-2019-12670 [MEDIUM] CWE-284 CVE-2019-12670: A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attac A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx Guest Shell to modify the namespace container protections on an affected device. The vulnerability is due to insufficient file permissions. An attacker could exploit this vulnerability by modifying files that they should not have ac
nvd
CVE-2023-20081P4MEDIUMCVSS 5.9v17.8.12023-03-23
CVE-2023-20081 [MEDIUM] CWE-122 CVE-2023-20081: A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) S A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu
nvd
CVE-2017-12211P4MEDIUMCVSS 5.3v3.16.12017-09-07
CVE-2017-12211 [MEDIUM] CWE-399 CVE-2017-12211: A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IO A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device. The vulnerability is due to IPv6 sub block corruption. An attacker could exploit this vulnerability by polling the affected device IPv6 info
nvd
CVE-2017-6624P4MEDIUMCVSS 5.3v15.5\(3\)m2017-05-03
CVE-2017-6624 [MEDIUM] CWE-264 CVE-2017-6624: A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an un A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections component of the affected software. An attacker could exploit this vulnerability to place unauthorized
nvd
CVE-2009-1168P4HIGHCVSS 7.1v12.0\(32\)s12v12.0\(32\)s13+9 more2009-07-30
CVE-2009-1168 [HIGH] CWE-399 CVE-2009-1168: Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12. Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (memory corrup
nvd
CVE-2025-20196P4MEDIUMCVSS 5.3vN/A2025-05-07
CVE-2025-20196 [MEDIUM] CWE-307 CVE-2025-20196: A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application hosting environment to stop responding, resulting in a denial of service (DoS) condition. This vulnerability is due to the improper handling of HTTP reques
nvd
CVE-2012-1312P4HIGHCVSS 7.1v15.1v15.22012-03-29
CVE-2012-1312 [HIGH] CWE-399 CVE-2012-1312: The MACE feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (de The MACE feature in Cisco IOS 15.1 and 15.2 allows remote attackers to cause a denial of service (device reload) via crafted transit traffic, aka Bug IDs CSCtq64987 and CSCtu57226.
nvd
CVE-2010-2830P4HIGHCVSS 7.1v12.2v12.2b+161 more2010-09-23
CVE-2010-2830 [HIGH] CVE-2010-2830: The IGMPv3 implementation in Cisco IOS 12.2, 12.3, 12.4, and 15.0 and IOS XE 2.5.x before 2.5.2, whe The IGMPv3 implementation in Cisco IOS 12.2, 12.3, 12.4, and 15.0 and IOS XE 2.5.x before 2.5.2, when PIM is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed IGMP packet, aka Bug ID CSCte14603.
nvd
CVE-2015-0593P4HIGHCVSS 7.1v15.4\(1.12\)tv15.4\(1.19\)t2015-02-13
CVE-2015-0593 [HIGH] CWE-399 CVE-2015-0593: The Zone-Based Firewall implementation in Cisco IOS 12.4(122)T and earlier does not properly manage The Zone-Based Firewall implementation in Cisco IOS 12.4(122)T and earlier does not properly manage session-object structures, which allows remote attackers to cause a denial of service (device reload) via crafted network traffic, aka Bug ID CSCul65003.
nvd
CVE-2002-1360P4CRITICALCVSS 10.0v12.0sv12.0st+6 more2002-12-23
CVE-2002-1360 [CRITICAL] CWE-20 CVE-2002-1360: Multiple SSH2 servers and clients do not properly handle strings with null characters in them when t Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as implemented using languages such as C, as
nvd
CVE-2003-1398P4CRITICALCVSS 9.3v12.0v12.0s+10 more2003-12-31
CVE-2003-1398 [CRITICAL] CWE-200 CVE-2003-1398: Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, whic Cisco IOS 12.0 through 12.2, when IP routing is disabled, accepts false ICMP redirect messages, which allows remote attackers to cause a denial of service (network routing modification).
nvd
CVE-2015-0771P4MEDIUMCVSS 6.3v12.2\(33\)sxj8v12.2sxj2015-06-12
CVE-2015-0771 [MEDIUM] CWE-399 CVE-2015-0771: The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12.2 on Catalyst 6500 devices a The IKE implementation in the WS-IPSEC-3 service module in Cisco IOS 12.2 on Catalyst 6500 devices allows remote authenticated users to cause a denial of service (device reload) by sending a crafted message during IPsec tunnel setup, aka Bug ID CSCur70505.
nvd
CVE-2022-20727P4MEDIUMCVSS 6.7v15.2\(5\)e1v15.2\(6\)e0a+67 more2022-04-15
CVE-2022-20727 [MEDIUM] CWE-22 CVE-2022-20727: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2022-20677P4MEDIUMCVSS 6.7v17.6.12022-04-15
CVE-2022-20677 [MEDIUM] CWE-22 CVE-2022-20677: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2013-0149P4MEDIUMCVSS 5.8v12.0v12.0\(1\)+485 more2013-08-05
CVE-2013-0149 [MEDIUM] CVE-2013-0149: The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9 The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (ro
nvd