Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 26 of 30
CVE-2015-6294P4MEDIUMCVSS 6.1v15.2\(2\)ev15.2\(2\)e1+3 more2015-09-18
CVE-2015-6294 [MEDIUM] CWE-399 CVE-2015-6294: Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a deni
Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770.
nvd
CVE-2011-3274P4MEDIUMCVSS 6.1v12.2\(33\)srev12.2\(33\)sre0a+6 more2011-10-03
CVE-2011-3274 [MEDIUM] CVE-2011-3274: Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x
Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device crash) via a crafted IPv6 packet, related to an expired MPLS TTL, aka Bug ID CSCto07919.
nvd
CVE-2012-1327P4MEDIUMCVSS 6.1v12.3v12.4+2 more2012-05-03
CVE-2012-1327 [MEDIUM] CWE-284 CVE-2012-1327: dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remote attackers to cause
dot11t/t_if_dot11_hal_ath.c in Cisco IOS 12.3, 12.4, 15.0, and 15.1 allows remote attackers to cause a denial of service (assertion failure and reboot) via 802.11 wireless traffic, as demonstrated by a video call from Apple iOS 5.0 on an iPhone 4S, aka Bug ID CSCtt94391.
nvd
CVE-2015-0731P4MEDIUMCVSS 6.1v15.3\(3\)s1v15.3s2015-05-16
CVE-2015-0731 [MEDIUM] CWE-399 CVE-2015-0731: The ISDN implementation in Cisco IOS 15.3S allows remote attackers to cause a denial of service (dev
The ISDN implementation in Cisco IOS 15.3S allows remote attackers to cause a denial of service (device reload) via malformed Q931 SETUP messages, aka Bug ID CSCut37890.
nvd
CVE-2020-3201P4MEDIUMCVSS 6.0v12.2\(18\)ixav12.2\(18\)ixb+1668 more2020-06-03
CVE-2020-3201 [MEDIUM] CWE-20 CVE-2020-3201: A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS X
A vulnerability in the Tool Command Language (Tcl) interpreter of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker with privileged EXEC credentials to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient input validation of data passed to the Tcl interpreter.
nvd
CVE-2011-4007P4MEDIUMCVSS 5.4v15.0v15.12012-05-02
CVE-2011-4007 [MEDIUM] CWE-20 CVE-2011-4007: Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition"
Cisco IOS 15.0 and 15.1 and IOS XE 3.x do not properly handle the "set mpls experimental imposition" command, which allows remote attackers to cause a denial of service (device crash) via network traffic that triggers (1) fragmentation or (2) reassembly, aka Bug ID CSCtr56576.
nvd
CVE-2011-2586P4MEDIUMCVSS 5.4v12.4v15.02012-05-02
CVE-2011-2586 [MEDIUM] CWE-20 CVE-2011-2586: The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial o
The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.
nvd
CVE-2004-0710P4MEDIUMCVSS 5.0v12.2\(14\)syv12.2\(14\)za+6 more2004-07-27
CVE-2004-0710 [MEDIUM] CVE-2004-0710: IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Seri
IP Security VPN Services Module (VPNSM) in Cisco Catalyst 6500 Series Switch and the Cisco 7600 Series Internet Routers running IOS before 12.2(17b)SXA, before 12.2(17d)SXB, or before 12.2(14)SY03 could allow remote attackers to cause a denial of service (device crash and reload) via a malformed Internet Key Exchange (IKE) packet.
nvd
CVE-2011-1625P4MEDIUMCVSS 5.4v12.2v12.3+3 more2011-08-18
CVE-2011-1625 [MEDIUM] CVE-2011-1625: Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configure
Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka Bug ID CSCtf74999, a different vulnerability than CVE-2007-0199, CVE-2008-1152, and CVE-2009-0629.
nvd
CVE-2004-0589P4MEDIUMCVSS 4.3≥ 11.1, ≤ 12.2\(14\)sx22004-08-06
CVE-2004-0589 [MEDIUM] CVE-2004-0589: Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allo
Cisco IOS 11.1(x) through 11.3(x) and 12.0(x) through 12.2(x), when configured for BGP routing, allows remote attackers to cause a denial of service (device reload) via malformed BGP (1) OPEN or (2) UPDATE messages.
nvd
CVE-2012-3915P4MEDIUMCVSS 5.0v15.22012-09-16
CVE-2012-3915 [MEDIUM] CWE-119 CVE-2012-3915: The DMVPN tunnel implementation in Cisco IOS 15.2 allows remote attackers to cause a denial of servi
The DMVPN tunnel implementation in Cisco IOS 15.2 allows remote attackers to cause a denial of service (persistent IKE state) via a large volume of hub-to-spoke traffic, aka Bug ID CSCtq39602.
nvd
CVE-2011-4015P4MEDIUMCVSS 5.0v15.2s2012-05-02
CVE-2011-4015 [MEDIUM] CWE-20 CVE-2011-4015: Cisco IOS 15.2S allows remote attackers to cause a denial of service (interface queue wedge) via mal
Cisco IOS 15.2S allows remote attackers to cause a denial of service (interface queue wedge) via malformed UDP traffic on port 465, aka Bug ID CSCts48300.
nvd
CVE-2005-2451P4LOWCVSS 2.1v12.0sv12.0sl+144 more2005-08-03
CVE-2005-2451 [LOW] CVE-2005-2451: Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a l
Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.
nvd
CVE-2014-3262P4MEDIUMCVSS 4.3≤ 15.3\(3\)sv15.3\(3\)m+2 more2014-05-16
CVE-2014-3262 [MEDIUM] CWE-20 CVE-2014-3262: The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS X
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.
nvd
CVE-2020-3231P4MEDIUMCVSS 4.7v15.2\(5\)e2v15.2\(5\)ex+20 more2020-06-03
CVE-2020-3231 [MEDIUM] CWE-284 CVE-2020-3231: A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CD
A vulnerability in the 802.1X feature of Cisco Catalyst 2960-L Series Switches and Cisco Catalyst CDB-8P Switches could allow an unauthenticated, adjacent attacker to forward broadcast traffic before being authenticated on the port. The vulnerability exists because broadcast traffic that is received on the 802.1X-enabled port is mishandled. An attacke
nvd
CVE-2007-2587P4MEDIUMCVSS 6.3≥ 11.3, ≤ 12.42007-05-10
CVE-2007-2587 [MEDIUM] CVE-2007-2587: The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denia
The IOS FTP Server in Cisco IOS 11.3 through 12.4 allows remote authenticated users to cause a denial of service (IOS reload) via unspecified vectors involving transferring files (aka bug ID CSCse29244).
nvd
CVE-2019-1758P4MEDIUMCVSS 4.3v12.2\(33\)sxj6v12.2\(33\)sxj7+70 more2019-03-28
CVE-2019-1758 [MEDIUM] CWE-287 CVE-2019-1758: A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could
A vulnerability in 802.1x function of Cisco IOS Software on the Catalyst 6500 Series Switches could allow an unauthenticated, adjacent attacker to access the network prior to authentication. The vulnerability is due to how the 802.1x packets are handled in the process path. An attacker could exploit this vulnerability by attempting to connect to the ne
nvd
CVE-2015-0708P4MEDIUMCVSS 6.1v15.4\(3\)sv15.4\(3\)s1+5 more2015-04-29
CVE-2015-0708 [MEDIUM] CWE-399 CVE-2015-0708: Cisco IOS 15.4S, 15.4SN, and 15.5S and IOS XE 3.13S and 3.14S allow remote attackers to cause a deni
Cisco IOS 15.4S, 15.4SN, and 15.5S and IOS XE 3.13S and 3.14S allow remote attackers to cause a denial of service (device crash) by including an IA_NA option in a DHCPv6 Solicit message on the local network, aka Bug ID CSCur29956.
nvd
CVE-2005-0186P4MEDIUMCVSS 5.0v12.1ydv12.2t+2 more2005-01-19
CVE-2005-0186 [MEDIUM] CVE-2005-0186: Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallMa
Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.
nvd
CVE-2012-3062P4MEDIUMCVSS 5.7v15.12014-04-23
CVE-2012-3062 [MEDIUM] CWE-20 CVE-2012-3062: Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remo
Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via MLD packets on a network that contains many IPv6 hosts, aka Bug ID CSCtr88193.
nvd