cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 21 of 30
CVE-2004-1776P4HIGHCVSS 7.5v12.1\(3\)v12.1\(3\)t2001-02-28
CVE-2004-1776 [HIGH] CVE-2004-1776: Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data Cisco IOS 12.1(3) and 12.1(3)T allows remote attackers to read and modify device configuration data via the cable-docsis read-write community string used by the Data Over Cable Service Interface Specification (DOCSIS) standard.
nvd
CVE-2006-0340P4HIGHCVSS 7.1v12.0v12.0s+106 more2006-01-21
CVE-2006-0340 [HIGH] CWE-20 CVE-2006-0340: Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 1 Unspecified vulnerability in Stack Group Bidding Protocol (SGBP) support in Cisco IOS 12.0 through 12.4 running on various Cisco products, when SGBP is enabled, allows remote attackers on the local network to cause a denial of service (device hang and network traffic loss) via a crafted UDP packet to port 9900.
nvd
CVE-2012-3946P4MEDIUMCVSS 5.0≤ 15.32014-04-24
CVE-2012-3946 [MEDIUM] CWE-264 CVE-2012-3946: Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunis Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.
nvd
CVE-2010-0577P4HIGHCVSS 7.1v12.2bv12.2bc+134 more2010-03-25
CVE-2010-0577 [HIGH] CWE-399 CVE-2010-0577: Cisco IOS 12.2 through 12.4, when certain PMTUD, SNAT, or window-size configurations are used, allow Cisco IOS 12.2 through 12.4, when certain PMTUD, SNAT, or window-size configurations are used, allows remote attackers to cause a denial of service (infinite loop, and device reload or hang) via a TCP segment with crafted options, aka Bug ID CSCsz75186.
nvd
CVE-2015-6366P4MEDIUMCVSS 5.0v15.2\(4\)m6v15.4\(3\)s2015-11-13
CVE-2015-6366 [MEDIUM] CWE-284 CVE-2015-6366: Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, whi Cisco IOS 15.2(04)M6 and 15.4(03)S lets physical-interface ACLs supersede tunnel-interface ACLs, which allows remote attackers to bypass intended network-traffic restrictions in opportunistic circumstances by using a tunnel, aka Bug ID CSCur01042.
nvd
CVE-2012-0338P4MEDIUMCVSS 5.0v12.2v12.3+2 more2012-05-02
CVE-2012-0338 [MEDIUM] CWE-20 CVE-2012-0338: Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of a Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish SSH connections from arbitrary source IP addresses via a standard SSH client, aka Bug ID CSCsv86113.
nvd
CVE-2008-1150P4HIGHCVSS 7.1≤ 12.22008-03-27
CVE-2008-1150 [HIGH] CWE-399 CVE-2008-1150: The virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attacker The virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (resource exhaustion) via a series of PPTP sessions, related to the persistence of interface descriptor block (IDB) data structures after process termination, aka bug ID CSCdv59309.
nvd
CVE-2013-1143P4HIGHCVSS 7.1v12.2v15.0+4 more2013-03-28
CVE-2013-1143 [HIGH] CWE-119 CVE-2013-1143: The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3 The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory access and device reload) via a traffic engineering PATH message in an RSVP packet, aka Bug ID CSC
nvd
CVE-2012-1324P4HIGHCVSS 7.1v15.1v15.22012-05-03
CVE-2012-1324 [HIGH] CWE-362 CVE-2012-1324: Race condition in the Zone-Based Firewall in Cisco IOS 15.1 and 15.2, when IPS policies are configur Race condition in the Zone-Based Firewall in Cisco IOS 15.1 and 15.2, when IPS policies are configured, allows remote attackers to cause a denial of service (device crash) by sending IPv6 packets, aka Bug ID CSCtk53534.
nvd
CVE-2015-0607P4MEDIUMCVSS 4.3v15.4\(1\)tv15.4\(1\)t1+9 more2015-03-06
CVE-2015-0607 [MEDIUM] CWE-287 CVE-2015-0607: The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connection attempt with a blank password, aka Bug IDs CSCuo09
nvd
CVE-2009-0471P4MEDIUMCVSS 6.8v12.4\(23\)2009-02-06
CVE-2009-0471 [MEDIUM] CWE-352 CVE-2009-0471: Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remo Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the hostname command with a level/15/configure/-/hostname request.
nvd
CVE-2015-6263P4MEDIUMCVSS 6.3v15.4\(3\)m2.22015-10-12
CVE-2015-6263 [MEDIUM] CWE-399 CVE-2015-6263: The RADIUS client implementation in Cisco IOS 15.4(3)M2.2, when a shared RADIUS secret is configured The RADIUS client implementation in Cisco IOS 15.4(3)M2.2, when a shared RADIUS secret is configured, allows remote RADIUS servers to cause a denial of service (device reload) via malformed answers, aka Bug ID CSCuu59324.
nvd
CVE-2017-12304P4MEDIUMCVSS 6.1v15.7\(2.0z\)m2017-11-16
CVE-2017-12304 [MEDIUM] CWE-79 CVE-2017-12304: A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Soft A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface on an affected device. The vulnerability is due to insufficient validation of user-supplied input b
nvd
CVE-2025-20149P4MEDIUMCVSS 6.5v15.2(1)Sv15.2(2)S+737 more2025-09-24
CVE-2025-20149 [MEDIUM] CWE-120 CVE-2025-20149: A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authentica A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to a buffer overflow. An attacker with a low-privileged account could exploit this vulnerability by usi
nvd
CVE-1999-1466P4HIGHCVSS 7.5v8.2v8.3+2 more1992-12-10
CVE-1999-1466 [HIGH] CVE-1999-1466: Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access con Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.
nvd
CVE-2007-4291P4HIGHCVSS 7.1v12.0v12.1+3 more2007-08-09
CVE-2007-4291 [HIGH] CVE-2007-4291: Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service via (1) a malformed MGCP packet, which causes a device hang, aka CSCsf08998; a malformed H.323 packet, which causes a device crash, as identified by (2) CSCsi60004 with Proxy Unregistration and (3) CSCsg70474; and a malformed Real-time Transport Protocol (RTP) packet, which causes
nvd
CVE-2007-0918P4HIGHCVSS 7.1v12.3tv12.3xq+23 more2007-02-14
CVE-2007-0918 [HIGH] CVE-2007-0918: The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4X The ATOMIC.TCP signature engine in the Intrusion Prevention System (IPS) feature for Cisco IOS 12.4XA, 12.3YA, 12.3T, and other trains allows remote attackers to cause a denial of service (IPS crash and traffic loss) via unspecified manipulations that are not properly handled by the regular expression feature, as demonstrated using the 3123.0 (Netbus Pro Traffi
nvd
CVE-2008-3812P4HIGHCVSS 7.1v12.4tv12.4xe+4 more2008-09-26
CVE-2008-3812 [HIGH] CVE-2008-3812: Cisco IOS 12.4, when IOS firewall Application Inspection Control (AIC) with HTTP Deep Packet Inspect Cisco IOS 12.4, when IOS firewall Application Inspection Control (AIC) with HTTP Deep Packet Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed HTTP transit packet.
nvd
CVE-2010-4684P4HIGHCVSS 7.1fixed in 15.0\(1\)xa12011-01-07
CVE-2010-4684 [HIGH] CWE-20 CVE-2010-4684: Cisco IOS before 15.0(1)XA1, when certain TFTP debugging is enabled, allows remote attackers to caus Cisco IOS before 15.0(1)XA1, when certain TFTP debugging is enabled, allows remote attackers to cause a denial of service (device crash) via a TFTP copy over IPv6, aka Bug ID CSCtb28877.
nvd
CVE-2020-3477P4MEDIUMCVSS 5.5v16.3.112020-09-24
CVE-2020-3477 [MEDIUM] CWE-20 CVE-2020-3477: A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an aut A vulnerability in the CLI parser of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to access files from the flash: filesystem. The vulnerability is due to insufficient application of restrictions during the execution of a specific command. An attacker could exploit this vulnerability by using a specific comma
nvd
Cisco iOS vulnerabilities | cvebase