Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 25 of 30
CVE-2025-20137P4MEDIUMCVSS 4.7v15.2\(5a\)ev15.2\(5b\)e+68 more2025-05-07
CVE-2025-20137 [MEDIUM] CWE-284 CVE-2025-20137: A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running o
A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to bypass a configured ACL.
This vulnerability is due to the use of both an IPv4 ACL and a dynamic ACL of IP Source Guard on the same inte
nvd
CVE-2016-1425P4MEDIUMCVSS 6.5v15.0\(2\)sg5v15.1\(2\)sg3+3 more2016-07-03
CVE-2016-1425 [MEDIUM] CWE-119 CVE-2016-1425: Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cau
Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun66735.
nvd
CVE-2012-3895P4MEDIUMCVSS 6.3v15.0v15.0\(1\)se+3 more2012-09-16
CVE-2012-3895 [MEDIUM] CVE-2012-3895: Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device c
Cisco IOS 15.0 through 15.3 allows remote authenticated users to cause a denial of service (device crash) via an MVPNv6 update, aka Bug ID CSCty89224.
nvd
CVE-2012-3893P4MEDIUMCVSS 6.3v15.2v15.32012-09-16
CVE-2012-3893 [MEDIUM] CVE-2012-3893: The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a d
The FlexVPN implementation in Cisco IOS 15.2 and 15.3 allows remote authenticated users to cause a denial of service (spoke crash) via spoke-to-spoke traffic, aka Bug ID CSCtz02622.
nvd
CVE-2011-4231P4MEDIUMCVSS 6.3v15.1v15.22012-05-03
CVE-2011-4231 [MEDIUM] CWE-20 CVE-2011-4231: Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in u
Cisco IOS 15.1 and 15.2 and IOS XE 3.x, when configured as an IPsec hub with X.509 certificates in use, allows remote authenticated users to cause a denial of service (segmentation fault and device crash) via unspecified vectors, aka Bug ID CSCtq61128.
nvd
CVE-2016-6404P4MEDIUMCVSS 6.1v15.5\(2\)t2016-09-18
CVE-2016-6404 [MEDIUM] CWE-79 CVE-2016-6404: Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5
Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy19854.
nvd
CVE-2014-3409P4MEDIUMCVSS 6.1≤ 12.2\(33\)sre9a2014-10-25
CVE-2014-3409 [MEDIUM] CWE-399 CVE-2014-3409: The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and ear
The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (device reload) via malformed CFM packets, aka Bug ID CSCuq93406.
nvd
CVE-2005-0195P4MEDIUMCVSS 5.0v12.0sv12.0sx+74 more2005-05-02
CVE-2005-0195 [MEDIUM] CVE-2005-0195: Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart)
Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.
nvd
CVE-2012-5044P4MEDIUMCVSS 5.4≤ 15.2\(2\)t2014-04-23
CVE-2012-5044 [MEDIUM] CWE-119 CVE-2012-5044: Cisco IOS before 15.3(1)T, when media flow-around is not used, allows remote attackers to cause a de
Cisco IOS before 15.3(1)T, when media flow-around is not used, allows remote attackers to cause a denial of service (media loops and stack memory corruption) via VoIP traffic, aka Bug ID CSCub45809.
nvd
CVE-2012-1317P4MEDIUMCVSS 5.4v15.12014-04-23
CVE-2012-1317 [MEDIUM] CWE-119 CVE-2012-1317: The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial
The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.
nvd
CVE-2010-4687P4MEDIUMCVSS 5.0fixed in 15.0\(1\)xa12011-01-07
CVE-2010-4687 [MEDIUM] CWE-20 CVE-2010-4687: STCAPP (aka the SCCP telephony control application) on Cisco IOS before 15.0(1)XA1 does not properly
STCAPP (aka the SCCP telephony control application) on Cisco IOS before 15.0(1)XA1 does not properly handle multiple calls to a shared line, which allows remote attackers to cause a denial of service (port hang) by simultaneously ending two calls that were controlled by CallManager Express (CME), aka Bug ID CSCtd42552.
nvd
CVE-2012-1367P4MEDIUMCVSS 5.0v12.0v12.2+3 more2012-08-06
CVE-2012-1367 [MEDIUM] CWE-20 CVE-2012-1367: The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers
The MallocLite implementation in Cisco IOS 12.0, 12.2, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (Route Processor crash) via a BGP UPDATE message with a modified local-preference (aka LOCAL_PREF) attribute length, aka Bug ID CSCtq06538.
nvd
CVE-2011-2059P4MEDIUMCVSS 5.0fixed in 15.1\(4\)m1.32011-10-22
CVE-2011-2059 [MEDIUM] CWE-200 CVE-2011-2059: The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting
The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the IOS operating system via an ICMPv6 Echo Request packet containing a Hop-by-Hop (HBH) extension header (EH) with a 0x0c01050c value in the PadN option data, aka Bug ID CSCtq0
nvd
CVE-2012-0360P4MEDIUMCVSS 5.0v15.12014-04-23
CVE-2012-0360 [MEDIUM] CWE-399 CVE-2012-0360: Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers
Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.
nvd
CVE-2004-0081P4MEDIUMCVSS 5.0v12.1\(11\)ev12.1\(11b\)e+8 more2004-11-23
CVE-2004-0081 [MEDIUM] CVE-2004-0081: OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote atta
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
nvd
CVE-2005-1020P4HIGHCVSS 7.1v12.0v12.0\(23\)s4+335 more2005-05-02
CVE-2005-1020 [HIGH] CWE-287 CVE-2005-1020: Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of ser
Secure Shell (SSH) 2 in Cisco IOS 12.0 through 12.3 allows remote attackers to cause a denial of service (device reload) (1) via a username that contains a domain name when using a TACACS+ server to authenticate, (2) when a new SSH session is in the login phase and a currently logged in user issues a send command, or (3) when IOS is logging messages and
nvd
CVE-2017-6770P4MEDIUMCVSS 4.2v12.0\(1\)v12.0\(1\)t+3089 more2017-08-07
CVE-2017-6770 [MEDIUM] CWE-20 CVE-2017-6770: Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS
Cisco IOS 12.0 through 15.6, Adaptive Security Appliance (ASA) Software 7.0.1 through 9.7.1.2, NX-OS 4.0 through 12.0, and IOS XE 3.6 through 3.18 are affected by a vulnerability involving the Open Shortest Path First (OSPF) Routing Protocol Link State Advertisement (LSA) database. This vulnerability could allow an unauthenticated, remote attacker to t
nvd
CVE-2012-0362P4MEDIUMCVSS 4.3v12.2\(58\)sesv15.0\(1\)se2012-05-02
CVE-2012-0362 [MEDIUM] CWE-264 CVE-2012-0362: The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end wi
The extended ACL functionality in Cisco IOS 12.2(58)SE2 and 15.0(1)SE discards all lines that end with a log or time keyword, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by sending network traffic, aka Bug ID CSCts01106.
nvd
CVE-2015-4185P4MEDIUMCVSS 6.9v15.2\(4\)m6v15.2m2015-06-13
CVE-2015-4185 [MEDIUM] CWE-264 CVE-2015-4185: The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local u
The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session very soon after a TCL script execution, aka Bug ID CSCuq24202.
nvd
CVE-2005-0196P4MEDIUMCVSS 5.0v12.0v12.0da+194 more2005-05-02
CVE-2005-0196 [MEDIUM] CVE-2005-0196: Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, al
Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.
nvd