Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 27 of 30
CVE-2004-1111P4MEDIUMCVSS 5.0v12.2\(14\)szv12.2\(18\)ew+6 more2005-01-10
CVE-2004-1111 [MEDIUM] CVE-2004-1111: Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and oth
Cisco IOS 2.2(18)EW, 12.2(18)EWA, 12.2(14)SZ, 12.2(18)S, 12.2(18)SE, 12.2(18)SV, 12.2(18)SW, and other versions without the "no service dhcp" command, keep undeliverable DHCP packets in the queue instead of dropping them, which allows remote attackers to cause a denial of service (dropped traffic) via multiple undeliverable DHCP packets that exceed the input
nvd
CVE-2011-4019P4MEDIUMCVSS 5.4v12.4v15.0+2 more2012-05-03
CVE-2011-4019 [MEDIUM] CWE-399 CVE-2011-4019: Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM)
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883.
nvd
CVE-2000-0700P4MEDIUMCVSS 5.0v11.2v11.2\(8\)+13 more2000-10-20
CVE-2000-0700 [MEDIUM] CVE-2000-0700: Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11
Cisco Gigabit Switch Routers (GSR) with Fast Ethernet / Gigabit Ethernet cards, from IOS versions 11.2(15)GS1A up to 11.2(19)GS0.2 and some versions of 12.0, do not properly handle line card failures, which allows remote attackers to bypass ACLs or force the interface to stop forwarding packets.
nvd
CVE-2012-4658P4MEDIUMCVSS 5.0≤ 15.1\(1\)sy2v15.1+2 more2014-04-23
CVE-2012-4658 [MEDIUM] CWE-287 CVE-2012-4658: The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a d
The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.
nvd
CVE-2019-12668P4MEDIUMCVSS 4.8v15.2\(2\)ev15.2\(2\)ea+10 more2019-09-25
CVE-2019-12668 [MEDIUM] CWE-79 CVE-2019-12668: A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an auth
A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected software using the banner parameter. The vulnerability is due to insufficient input validation of the banner parameters
nvd
CVE-2022-20725P4MEDIUMCVSS 4.8v15.2\(5\)e1v15.2\(5\)e2c+68 more2022-04-15
CVE-2022-20725 [MEDIUM] CWE-22 CVE-2022-20725: Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platform
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or conduct a cross-site scripting (XSS)
nvd
CVE-2012-1361P4MEDIUMCVSS 4.3v15.1v15.22012-08-06
CVE-2012-1361 [MEDIUM] CWE-200 CVE-2012-1361: Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communicat
Cisco IOS 15.1 and 15.2, when the Multicast Music-on-Hold (MMoH) feature of Cisco Unified Communications Manager (CUCM) is enabled, allows remote attackers to obtain sensitive crosstalk information by listening during a PSTN call, aka Bug ID CSCtx77750.
nvd
CVE-2012-3918P4MEDIUMCVSS 4.3≤ 15.3\(3\)m2v15.3+5 more2014-04-23
CVE-2012-3918 [MEDIUM] CVE-2012-3918: Cisco IOS before 15.3(1)T on Cisco 2900 devices, when a VWIC2-2MFT-T1/E1 card is configured for TDM/
Cisco IOS before 15.3(1)T on Cisco 2900 devices, when a VWIC2-2MFT-T1/E1 card is configured for TDM/HDLC mode, allows remote attackers to cause a denial of service (serial-interface outage) via certain Frame Relay traffic, aka Bug ID CSCub13317.
nvd
CVE-2007-1258P4MEDIUMCVSS 6.1v12.2\(18\)sxf4v12.2sxa+3 more2007-03-03
CVE-2007-1258 [MEDIUM] CVE-2007-1258: Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 r
Unspecified vulnerability in Cisco IOS 12.2SXA, SXB, SXD, and SXF; and the MSFC2, MSFC2a and MSFC3 running in Hybrid Mode on Cisco Catalyst 6000, 6500 and Cisco 7600 series systems; allows remote attackers on a local network segment to cause a denial of service (software reload) via a certain MPLS packet.
nvd
CVE-2004-1454P4MEDIUMCVSS 5.0v12.0\(22\)sv12.0\(22\)s4+75 more2004-12-31
CVE-2004-1454 [MEDIUM] CVE-2004-1454: Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attacke
Cisco IOS 12.0S, 12.2, and 12.3, with Open Shortest Path First (OSPF) enabled, allows remote attackers to cause a denial of service (device reload) via a malformed OSPF packet.
nvd
CVE-2002-1024P4HIGHCVSS 7.1v12.0sv12.0sp+62 more2002-10-04
CVE-2002-1024 [HIGH] CVE-2002-1024: Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of servi
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
nvd
CVE-2007-0199P4MEDIUMCVSS 5.0≤ 12.4v11.02007-01-11
CVE-2007-0199 [MEDIUM] CVE-2007-0199: The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cau
The Data-link Switching (DLSw) feature in Cisco IOS 11.0 through 12.4 allows remote attackers to cause a denial of service (device reload) via "an invalid value in a DLSw message... during the capabilities exchange."
nvd
CVE-1999-1129P4HIGHCVSS 7.5v11.2\(8\)sa51999-09-01
CVE-1999-1129 [HIGH] CVE-1999-1129: Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into
Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.
nvd
CVE-2009-5039P4MEDIUMCVSS 5.0fixed in 15.0\(1\)xa2011-01-07
CVE-2009-5039 [MEDIUM] CWE-772 CVE-2009-5039: Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS befor
Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535.
nvd
CVE-2005-1021P4HIGHCVSS 7.1v12.0sv12.0sx+91 more2005-05-02
CVE-2005-1021 [HIGH] CWE-399 CVE-2005-1021: Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through 12.3, when authenticating against a TACA
Memory leak in Secure Shell (SSH) in Cisco IOS 12.0 through 12.3, when authenticating against a TACACS+ server, allows remote attackers to cause a denial of service (memory consumption) via an incorrect username or password.
nvd
CVE-2012-4651P4MEDIUMCVSS 4.3≤ 15.3\(3\)m2v15.3+5 more2014-04-23
CVE-2012-4651 [MEDIUM] CWE-189 CVE-2012-4651: Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of se
Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.
nvd
CVE-2007-4632P4MEDIUMCVSS 4.3v12.2ev12.2f+1 more2007-08-31
CVE-2007-4632 [MEDIUM] CVE-2007-4632: Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an admini
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authentication and obtain a terminal session, a different vulnerability than CVE-1999-0293 and CVE-2005-2105.
nvd
CVE-2015-6365P4MEDIUMCVSS 4.0v15.2\(4\)mv15.4\(3\)m2015-11-14
CVE-2015-6365 [MEDIUM] CWE-20 CVE-2015-6365: Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs,
Cisco IOS 15.2(04)M and 15.4(03)M lets physical-interface ACLs supersede virtual PPP interface ACLs, which allows remote authenticated users to bypass intended network-traffic restrictions in opportunistic circumstances by using PPP, aka Bug ID CSCur61303.
nvd
CVE-2005-0197P4MEDIUMCVSS 6.1v12.1tv12.2+3 more2005-05-02
CVE-2005-0197 [MEDIUM] CWE-16 CVE-2005-0197: Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed b
Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.
nvd
CVE-2002-0339P4MEDIUMCVSS 5.0v11.1ccv12.0+8 more2002-06-25
CVE-2002-0339 [MEDIUM] CVE-2002-0339: Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previ
Cisco IOS 11.1CC through 12.2 with Cisco Express Forwarding (CEF) enabled includes portions of previous packets in the padding of a MAC level packet when the MAC packet's length is less than the IP level packet length.
nvd