cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 22 of 30
CVE-2012-4617P4HIGHCVSS 7.1v15.22012-09-27
CVE-2012-4617 [HIGH] CWE-20 CVE-2012-4617: The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2. The BGP implementation in Cisco IOS 15.2, IOS XE 3.5.xS before 3.5.2S, and IOS XR 4.1.0 through 4.2.2 allows remote attackers to cause a denial of service (multiple connection resets) by leveraging a peer relationship and sending a malformed attribute, aka Bug IDs CSCtt35379, CSCty58300, CSCtz63248, and CSCtz62914.
nvd
CVE-2007-4293P4HIGHCVSS 7.1v12.0v12.1+3 more2007-08-09
CVE-2007-4293 [HIGH] CVE-2007-4293: Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device crash) via (1) "abnormal" MGCP messages, aka CSCsd81407; and (2) a large facsimile packet, aka CSCej20505.
nvd
CVE-2012-0339P4MEDIUMCVSS 5.0v12.2v12.3+2 more2012-05-02
CVE-2012-0339 [MEDIUM] CWE-20 CVE-2012-0339: Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of a Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID CSCsi77774.
nvd
CVE-2012-5017P4MEDIUMCVSS 6.8≤ 15.1\(1\)syv15.12014-04-23
CVE-2012-5017 [MEDIUM] CWE-20 CVE-2012-5017: Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device r Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.
nvd
CVE-2002-2208P4HIGHCVSS 7.8v11.3v12.0+2 more2002-12-31
CVE-2002-2208 [HIGH] CVE-2002-2208: Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 an Extended Interior Gateway Routing Protocol (EIGRP), as implemented in Cisco IOS 11.3 through 12.2 and other products, allows remote attackers to cause a denial of service (flood) by sending a large number of spoofed EIGRP neighbor announcements, which results in an ARP storm on the local network.
nvd
CVE-2010-3050P4MEDIUMCVSS 6.5≤ 12.2\(33\)sxh22017-09-25
CVE-2010-3050 [MEDIUM] CWE-20 CVE-2010-3050: Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot).
nvd
CVE-2019-1746P4MEDIUMCVSS 6.5v12.1\(6\)ea1v12.1\(6\)ea1a+472 more2019-03-28
CVE-2019-1746 [MEDIUM] CWE-20 CVE-2019-1746: A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and C A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation when processing CMP management packets. An attacker cou
nvd
CVE-2018-0197P4MEDIUMCVSS 6.5v12.1\(5c\)exv12.1\(5c\)ex1+1058 more2018-10-05
CVE-2018-0197 [MEDIUM] CWE-20 CVE-2018-0197: A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE A vulnerability in the VLAN Trunking Protocol (VTP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to corrupt the internal VTP database on an affected device and cause a denial of service (DoS) condition. The vulnerability is due to a logic error in how the affected software handles a subset
nvd
CVE-2017-6665P4MEDIUMCVSS 6.5v15.2\(3\)ev15.2\(3\)e1+115 more2017-08-07
CVE-2017-6665 [MEDIUM] CWE-319 CVE-2017-6665: A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to reset the Autonomic Control Plane (ACP) of an affected system and view ACP packets that are transferred in clear text within an affected system, an Information Disclosure Vulnerability. More Informatio
nvd
CVE-2022-20761P4MEDIUMCVSS 6.5v15.4\(1\)cgv15.4\(2\)cg+84 more2022-04-15
CVE-2022-20761 [MEDIUM] CWE-248 CVE-2022-20761: A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Ser A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an unauthenticated, adjacent attacker to cause a denial of service condition on an affected device. This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit
nvd
CVE-2008-1156P4MEDIUMCVSS 5.1v12.0v12.22008-03-27
CVE-2008-1156 [MEDIUM] CWE-16 CVE-2008-1156: Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IO Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast states on the core routers" via a crafted Multicast Distribution Tree (MDT) Data Join message.
nvd
CVE-2014-3263P4MEDIUMCVSS 5.4v15.3\(3\)mv15.3m2014-05-16
CVE-2014-3263 [MEDIUM] CWE-20 CVE-2014-3263: The ScanSafe module in Cisco IOS 15.3(3)M allows remote attackers to cause a denial of service (devi The ScanSafe module in Cisco IOS 15.3(3)M allows remote attackers to cause a denial of service (device reload) via HTTPS packets that require tower processing, aka Bug ID CSCum97038.
nvd
CVE-2011-2395P4MEDIUMCVSS 5.0v4.1v4.1.1+1407 more2011-06-09
CVE-2011-2395 [MEDIUM] CWE-16 CVE-2011-2395: The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remo The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote attackers to bypass the Router Advertisement Guarding functionality via a fragmented IPv6 packet in which the Router Advertisement (RA) message is contained in the second fragment, as demonstrated by (1) a packet in which the first fragment contains a
nvd
CVE-2016-1378P4MEDIUMCVSS 5.3v15.1\(1\)sgv15.1\(1\)sg1+26 more2016-04-14
CVE-2016-1378 [MEDIUM] CWE-200 CVE-2016-1378: Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensit Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62591.
nvd
CVE-2022-20724P4MEDIUMCVSS 5.3v15.2\(5\)e1v15.2\(5\)e2c+68 more2022-04-15
CVE-2022-20724 [MEDIUM] CWE-22 CVE-2022-20724: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2015-4202P4MEDIUMCVSS 5.0v12.2\(33\)schv12.2sch2015-06-20
CVE-2015-4202 [MEDIUM] CWE-200 CVE-2015-4202: Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restri Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service, which allows remote attackers to obtain potentially sensitive MAC address and network-utilization information via crafted IPDR packets, aka Bug ID CSCua39203.
nvd
CVE-2008-3802P4HIGHCVSS 7.1v12.2bv12.2bx+83 more2008-09-26
CVE-2008-3802 [HIGH] CVE-2008-3802: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4, when VoIP is configured, allows remote attackers to cause a denial of service (device reload) via unspecified valid SIP messages, aka Cisco bug ID CSCsk42759, a different vulnerability than CVE-2008-3800 and CVE-2008-3801.
nvd
CVE-2009-0635P4HIGHCVSS 7.1v12.4tv12.4xz+1 more2009-03-27
CVE-2009-0635 [HIGH] CWE-399 CVE-2009-0635: Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows remote attackers to cause a denial of service (memory consumption and device crash) via a sequence of TCP packets.
nvd
CVE-2014-3293P4MEDIUMCVSS 5.0v15.4\(3\)s0b2014-10-28
CVE-2014-3293 [MEDIUM] CWE-399 CVE-2014-3293: Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet proc Cisco IOS 15.4(3)S0b on ASR901 devices makes incorrect decisions to use the CPU for IPv4 packet processing, which allows remote attackers to cause a denial of service (BGP neighbor flapping) by sending many crafted IPv4 packets, aka Bug ID CSCuo29736.
nvd
CVE-2004-1775P4MEDIUMCVSS 5.0v12.0dav12.0db+65 more2004-12-31
CVE-2004-1775 [MEDIUM] CVE-2004-1775: Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and I Cisco VACM (View-based Access Control MIB) for Catalyst Operating Software (CatOS) 5.5 and 6.1 and IOS 12.0 and 12.1 allows remote attackers to read and modify device configuration via the read-write community string.
nvd