Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 24 of 30
CVE-2018-0466P4MEDIUMCVSS 6.5v16.2.12018-10-05
CVE-2018-0466 [MEDIUM] CWE-399 CVE-2018-0466: A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and I
A vulnerability in the Open Shortest Path First version 3 (OSPFv3) implementation in Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to cause an affected device to reload. The vulnerability is due to incorrect handling of specific OSPFv3 packets. An attacker could exploit this vulnerability by sending crafted OSPFv3 Lin
nvd
CVE-2016-1424P4MEDIUMCVSS 6.5v15.2\(1\)t1.11v15.2\(2\)tst2016-06-19
CVE-2016-1424 [MEDIUM] CWE-119 CVE-2016-1424: Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device c
Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun63132.
nvd
CVE-2012-1366P4MEDIUMCVSS 6.1v15.12014-04-23
CVE-2012-1366 [MEDIUM] CWE-20 CVE-2012-1366: Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is
Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.
nvd
CVE-2009-2049P4MEDIUMCVSS 5.4v12.0\(32\)s12v12.0\(32\)s13+9 more2009-07-30
CVE-2009-2049 [MEDIUM] CWE-16 CVE-2009-2049: Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.
Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1 through 12.2(33)SXI2, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of
nvd
CVE-2013-6693P4MEDIUMCVSS 5.4≤ 15.3\(3\)sv15.3\(2\)s+1 more2013-11-22
CVE-2013-6693 [MEDIUM] CWE-119 CVE-2013-6693: The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are config
The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345.
nvd
CVE-2014-3347P4MEDIUMCVSS 5.4v15.1\(4\)m22014-08-28
CVE-2014-3347 [MEDIUM] CWE-399 CVE-2014-3347: Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows
Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module, aka Bug ID CS
nvd
CVE-2015-6343P4MEDIUMCVSS 5.0v15.5\(3\)m2015-10-31
CVE-2015-6343 [MEDIUM] CWE-399 CVE-2015-6343: The SIP implementation in Cisco IOS 15.5(3)M on Cisco Unified Border Element (CUBE) devices allows r
The SIP implementation in Cisco IOS 15.5(3)M on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service via crafted SIP messages, aka Bug ID CSCuv79202.
nvd
CVE-2014-2143P4MEDIUMCVSS 5.0≤ 15.4\(1\)tv15.0+11 more2014-04-04
CVE-2014-2143 [MEDIUM] CVE-2014-2143: The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause
The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.
nvd
CVE-2015-6429P4MEDIUMCVSS 5.0v15.4\(3\)sv15.5\(1\)s+9 more2015-12-19
CVE-2015-6429 [MEDIUM] CWE-19 CVE-2015-6429: The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote at
The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a crafted IKEv1 packet to a tunnel endpoint, aka Bug ID CSCuw08236.
nvd
CVE-2002-1706P4HIGHCVSS 7.5≥ 11.3, ≤ 12.22002-12-31
CVE-2002-1706 [HIGH] CWE-347 CVE-2002-1706: Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband
Cisco IOS software 11.3 through 12.2 running on Cisco uBR7200 and uBR7100 series Universal Broadband Routers allows remote attackers to modify Data Over Cable Service Interface Specification (DOCSIS) settings via a DOCSIS file without a Message Integrity Check (MIC) signature, which is approved by the router.
nvd
CVE-2008-1151P4HIGHCVSS 7.1≤ 12.22008-03-27
CVE-2008-1151 [HIGH] CWE-399 CVE-2008-1151: Memory leak in the virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows
Memory leak in the virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (memory consumption) via a series of PPTP sessions, related to "dead memory" that remains allocated after process termination, aka bug ID CSCsj58566.
nvd
CVE-2009-5040P4MEDIUMCVSS 6.8≤ 15.0xav4.1+1548 more2011-01-07
CVE-2009-5040 [MEDIUM] CWE-399 CVE-2009-5040: CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.
nvd
CVE-2004-0112P4MEDIUMCVSS 5.0v12.1\(11\)ev12.1\(11b\)e+8 more2004-11-23
CVE-2004-0112 [MEDIUM] CWE-125 CVE-2004-0112: The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.
nvd
CVE-2015-6359P4MEDIUMCVSS 6.1v15.2\(4\)ev15.2\(4\)pi+3 more2015-12-15
CVE-2015-6359 [MEDIUM] CWE-119 CVE-2015-6359: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on AS
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND messages, aka Bug ID CSCup28217.
nvd
CVE-2003-0512P4MEDIUMCVSS 5.0v12.0\(24\)s1v12.0\(24.2\)s+7 more2003-08-27
CVE-2003-0512 [MEDIUM] CWE-310 CVE-2003-0512: Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password
Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allows remote attackers to identify valid usernames on the system and conduct brute force password guessing, as reported for the Aironet Bridge.
nvd
CVE-2011-4016P4MEDIUMCVSS 5.4v12.2v15.0+2 more2012-05-02
CVE-2011-4016 [MEDIUM] CWE-20 CVE-2011-4016: The PPP implementation in Cisco IOS 12.2 and 15.0 through 15.2, when Point-to-Point Termination and
The PPP implementation in Cisco IOS 12.2 and 15.0 through 15.2, when Point-to-Point Termination and Aggregation (PTA) and L2TP are used, allows remote attackers to cause a denial of service (device crash) via crafted network traffic, aka Bug ID CSCtf71673.
nvd
CVE-2016-1459P4MEDIUMCVSS 5.3v12.4\(4\)xc7v12.4\(15\)t17+24 more2016-07-17
CVE-2016-1459 [MEDIUM] CWE-399 CVE-2016-1459: Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users t
Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via crafted attributes in a BGP message, aka Bug ID CSCuz21061.
nvd
CVE-2018-0123P4MEDIUMCVSS 5.5v16.7\(1\)2018-02-08
CVE-2018-0123 [MEDIUM] CWE-22 CVE-2018-0123: A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow
A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to use certain diagnostic shell commands that can overwrite system files. These system files may be sensitive and should not be able to be overwritten by a user of the diagnostic shell. The vulnerability is due to lack o
nvd
CVE-2014-3268P4MEDIUMCVSS 5.0v15.2\(4\)m42014-05-20
CVE-2014-3268 [MEDIUM] CWE-20 CVE-2014-3268: Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause
Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and traffic-processing outage) via crafted RTCP packets, aka Bug ID CSCuj72215.
nvd
CVE-2012-5036P4MEDIUMCVSS 6.8v12.2\(33\)sxi4v12.2\(33\)sxi5+4 more2014-04-23
CVE-2012-5036 [MEDIUM] CWE-399 CVE-2012-5036: Cisco IOS before 12.2(50)SY1 allows remote authenticated users to cause a denial of service (memory
Cisco IOS before 12.2(50)SY1 allows remote authenticated users to cause a denial of service (memory consumption) via a sequence of VTY management sessions (aka exec sessions), aka Bug ID CSCtn43662.
nvd