cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 23 of 30
CVE-2009-2862P4MEDIUMCVSS 4.3v12.2xnbv12.2xnc+5 more2009-09-28
CVE-2009-2862 [MEDIUM] CVE-2009-2862: The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12 The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CSCsw47076, CSCsv48603, CSCsy54122, and CSCsu50252.
nvd
CVE-2013-6686P4MEDIUMCVSS 6.8≤ 15.3v15.0+3 more2013-11-18
CVE-2013-6686 [MEDIUM] CWE-20 CVE-2013-6686: The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to c The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.
nvd
CVE-2015-0709P4MEDIUMCVSS 6.8v15.5\(3\)sv15.5s2015-04-29
CVE-2015-0709 [MEDIUM] CWE-399 CVE-2015-0709: Cisco IOS 15.5S and IOS XE allow remote authenticated users to cause a denial of service (device cra Cisco IOS 15.5S and IOS XE allow remote authenticated users to cause a denial of service (device crash) by leveraging knowledge of the RADIUS secret and sending crafted RADIUS packets, aka Bug ID CSCur21348.
nvd
CVE-2012-5014P4MEDIUMCVSS 6.3≤ 15.1\(1\)sy3v15.1+3 more2014-04-23
CVE-2012-5014 [MEDIUM] CVE-2012-5014: Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device cr Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.
nvd
CVE-2016-6473P4MEDIUMCVSS 6.5v15.0\(2\)se8v15.2\(2\)e1+5 more2016-12-14
CVE-2016-6473 [MEDIUM] CWE-74 CVE-2016-6473: A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unau A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2 network storm. More Information: CSCuu69332, CSCux07028. Known Affected Releases: 15.2(3)E. Known Fixed Releases: 12.2(50)SE4 12.2(50)SE5 12.2(50)SQ5 12.2(50)SQ6 12.2(50)SQ7 12.2(52)EY4 12.2(52)SE1 12.2(5
nvd
CVE-2012-1338P4MEDIUMCVSS 6.3v15.0v15.12012-08-06
CVE-2012-1338 [MEDIUM] CWE-362 CVE-2012-1338: Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users Cisco IOS 15.0 and 15.1 on Catalyst 3560 and 3750 series switches allows remote authenticated users to cause a denial of service (device reload) by completing local web authentication quickly, aka Bug ID CSCts88664.
nvd
CVE-2015-0687P4MEDIUMCVSS 6.3v15.1\(2\)sg4v15.1sg2015-04-03
CVE-2015-0687 [MEDIUM] CWE-399 CVE-2015-0687: The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (VSS) is configured, allows remote authenticated users to cause a denial of service (device crash) by performing SNMP polling, aka Bug ID CSCuq04574.
nvd
CVE-2016-6403P4MEDIUMCVSS 5.9≤ 15.6\(1\)t2016-09-18
CVE-2016-6403 [MEDIUM] CWE-399 CVE-2016-6403: The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is e The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCuy82904, CSCuy82909, and CSCuy82912.
nvd
CVE-2015-4203P4MEDIUMCVSS 5.4v12.2\(33\)schv12.2sch2015-06-23
CVE-2015-4203 [MEDIUM] CWE-362 CVE-2015-4203: Race condition in Cisco IOS 12.2SCH in the Performance Routing Engine (PRE) module on uBR10000 devic Race condition in Cisco IOS 12.2SCH in the Performance Routing Engine (PRE) module on uBR10000 devices, when NetFlow and an MPLS IPv6 VPN are configured, allows remote attackers to cause a denial of service (PXF process crash) by sending malformed MPLS 6VPE packets quickly, aka Bug ID CSCud83396.
nvd
CVE-2005-4258P4HIGHCVSS 7.8v11.2\(8.2\)sa6v12.0\(5.2\)xu2005-12-15
CVE-2005-4258 [HIGH] CVE-2005-4258: Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device cras Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown; the details are obtained solely from the BID.
nvd
CVE-2008-3803P4MEDIUMCVSS 5.1v12.0sv12.0sx+1 more2008-09-26
CVE-2008-3803 [MEDIUM] CVE-2008-3803: A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with A "logic error" in Cisco IOS 12.0 through 12.4, when a Multiprotocol Label Switching (MPLS) VPN with extended communities is configured, sometimes causes a corrupted route target (RT) to be used, which allows remote attackers to read traffic from other VPNs in opportunistic circumstances.
nvd
CVE-2008-3804P4HIGHCVSS 7.1v12.2v12.42008-09-26
CVE-2008-3804 [HIGH] CVE-2008-3804: Unspecified vulnerability in the Multi Protocol Label Switching (MPLS) Forwarding Infrastructure (MF Unspecified vulnerability in the Multi Protocol Label Switching (MPLS) Forwarding Infrastructure (MFI) in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (memory corruption) via crafted packets for which the software path is used.
nvd
CVE-2002-2239P4HIGHCVSS 7.8v12.1e2002-12-31
CVE-2002-2239 [HIGH] CWE-20 CVE-2002-2239: The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1( The Cisco Optical Service Module (OSM) for the Catalyst 6500 and 7600 series running Cisco IOS 12.1(8)E through 12.1(13.4)E allows remote attackers to cause a denial of service (hang) via a malformed packet.
nvd
CVE-2016-6398P4MEDIUMCVSS 5.3v15.5\(3\)m2016-09-12
CVE-2016-6398 [MEDIUM] CWE-200 CVE-2016-6398: The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remo The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from earlier network communication by reading packet data, aka Bug ID CSCvb16274.
nvd
CVE-1999-0161P4HIGHCVSS 7.5v10.3\(3.4\)v10.3\(4.2\)1995-07-31
CVE-1999-0161 [HIGH] CVE-1999-0161: In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could by In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.
nvd
CVE-1999-1306P4HIGHCVSS 7.5≤ 9.11992-12-10
CVE-1999-1306 [HIGH] CVE-1999-1306: Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.
nvd
CVE-1999-0160P4HIGHCVSS 7.5v4.1v9.1+5 more1997-10-01
CVE-1999-0160 [HIGH] CVE-1999-0160: Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unau Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.
nvd
CVE-2015-0610P4MEDIUMCVSS 4.3≤ 15.5\(2\)tv15.5\(1\)t+2 more2015-02-12
CVE-2015-0610 [MEDIUM] CWE-362 CVE-2015-0610: Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attac Race condition in the object-group ACL feature in Cisco IOS 15.5(2)T and earlier allows remote attackers to bypass intended access restrictions via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCun21071.
nvd
CVE-2012-5422P4MEDIUMCVSS 6.8≤ 15.3\(2\)sv15.32014-04-23
CVE-2012-5422 [MEDIUM] CVE-2012-5422: Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated users to cause a denial of service (spurious errors) via unknown vectors, aka Bug ID CSCub61009.
nvd
CVE-2012-5030P4MEDIUMCVSS 6.5≤ 15.2\(4\)s52017-08-02
CVE-2012-5030 [MEDIUM] CWE-399 CVE-2012-5030: Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote aut Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote authenticated users to cause a denial of service (CPU consumption, watchdog timeout, crash) by walking specific SNMP objects.
nvd
Cisco iOS vulnerabilities | cvebase