cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 28 of 30
CVE-2012-5039P4MEDIUMCVSS 4.3≤ 12.2\(50\)sy2014-04-23
CVE-2012-5039 [MEDIUM] CWE-399 CVE-2012-5039: The BGP Router process in Cisco IOS before 12.2(50)SY1 allows remote attackers to cause a denial of The BGP Router process in Cisco IOS before 12.2(50)SY1 allows remote attackers to cause a denial of service (memory consumption) via vectors involving BGP path attributes, aka Bug ID CSCsw63003.
nvd
CVE-2005-3669P4MEDIUMCVSS 5.0v12.2sxdv12.3t+35 more2005-11-18
CVE-2005-3669 [MEDIUM] CVE-2005-3669: Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation i Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the Cisco advisory, it is unclear whic
nvd
CVE-2019-1761P4MEDIUMCVSS 4.3v12.2\(6\)i1v12.2\(33\)cx+1488 more2019-03-28
CVE-2019-1761 [MEDIUM] CWE-665 CVE-2019-1761: A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficient memory initialization. An attacker could exploit this vulnerability by receiving HSRPv2 tra
nvd
CVE-2001-1183P4MEDIUMCVSS 5.0v12.1ev12.1ez+11 more2001-07-12
CVE-2001-1183 [MEDIUM] CVE-2001-1183: PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service PPTP implementation in Cisco IOS 12.1 and 12.2 allows remote attackers to cause a denial of service (crash) via a malformed packet.
nvd
CVE-2001-1434P4MEDIUMCVSS 5.0v12.0v12.0\(1\)+199 more2001-02-28
CVE-2001-1434 [MEDIUM] CVE-2001-1434: Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topolo Cisco IOS 12.0(5)XU through 12.1(2) allows remote attackers to read system administration and topology information via an "snmp-server host" command, which creates a readable "community" community string if one has not been previously created.
nvd
CVE-2004-0714P4MEDIUMCVSS 5.0v12.0\(23\)s4v12.0\(23\)s5+60 more2004-07-27
CVE-2004-0714 [MEDIUM] CVE-2004-0714: Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited ope Cisco Internetwork Operating System (IOS) 12.0S through 12.3T attempts to process SNMP solicited operations on improper ports (UDP 162 and a randomly chosen UDP port), which allows remote attackers to cause a denial of service (device reload and memory corruption).
nvd
CVE-2001-1071P4MEDIUMCVSS 5.0v11.1v11.2+4 more2001-10-09
CVE-2001-1071 [MEDIUM] CVE-2001-1071: Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a Cisco IOS 12.2 and earlier running Cisco Discovery Protocol (CDP) allows remote attackers to cause a denial of service (memory consumption) via a flood of CDP neighbor announcements.
nvd
CVE-2010-3049P4MEDIUMCVSS 5.5≤ 12.2\(33\)sxh22017-09-25
CVE-2010-3049 [MEDIUM] CWE-20 CVE-2010-3049: Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot). Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).
nvd
CVE-2003-0851P4MEDIUMCVSS 5.0v12.1\(11\)ev12.1\(11b\)e+2 more2003-12-01
CVE-2003-0851 [MEDIUM] CVE-2003-0851: OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
nvd
CVE-2022-20661P4MEDIUMCVSS 4.6≥ 15.2\(5\)ex, < 15.2\(7\)e5v15.2\(8\)e2022-04-15
CVE-2022-20661 [MEDIUM] CWE-1221 CVE-2022-20661: Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catal Multiple vulnerabilities that affect Cisco Catalyst Digital Building Series Switches and Cisco Catalyst Micro Switches could allow an attacker to execute persistent code at boot time or to permanently prevent the device from booting, resulting in a permanent denial of service (DoS) condition. For more information about these vulnerabilities, see th
nvd
CVE-2019-1762P4MEDIUMCVSS 4.4v12.2\(6\)i1v15.1\(2\)sg8a+29 more2019-03-28
CVE-2019-1762 [MEDIUM] CWE-200 CVE-2019-1762: A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authen A vulnerability in the Secure Storage feature of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to access sensitive system information on an affected device. The vulnerability is due to improper memory operations performed at encryption time, when affected software handles configuration updates. An attacker could exploit th
nvd
CVE-2001-0650P4MEDIUMCVSS 5.0≤ 12.0v11.2+2 more2001-09-20
CVE-2001-0650 [MEDIUM] CVE-2001-0650: Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, v Cisco devices IOS 12.0 and earlier allow a remote attacker to cause a crash, or bad route updates, via malformed BGP updates with unrecognized transitive attribute.
nvd
CVE-2000-0268P4MEDIUMCVSS 5.0v11.3aav12.0\(2\)+11 more2000-04-20
CVE-2000-0268 [MEDIUM] CVE-2000-0268: Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON Cisco IOS 11.x and 12.x allows remote attackers to cause a denial of service by sending the ENVIRON option to the Telnet daemon before it is ready to accept it, which causes the system to reboot.
nvd
CVE-2002-1768P4MEDIUMCVSS 5.0v11.1v11.2+3 more2002-12-31
CVE-2002-1768 [MEDIUM] CVE-2002-1768: Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a de Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly sized UDP packets to the Hot Standby Routing Protocol (HSRP) port 1985.
nvd
CVE-2017-3803P4MEDIUMCVSS 4.7v15.2\(2\)e3v15.2\(4\)e12017-01-26
CVE-2017-3803 [MEDIUM] CWE-772 CVE-2017-3803: A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could a A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of service (DoS) condition. More Information: CSCva72252. Known Affected Releases: 15.2(2)E3 15.2(4)E1. Kno
nvd
CVE-2017-12289P4MEDIUMCVSS 4.4≤ 16.7.12017-10-19
CVE-2017-12289 [MEDIUM] CWE-200 CVE-2017-12289: A vulnerability in conditional, verbose debug logging for the IPsec feature of Cisco IOS XE Software A vulnerability in conditional, verbose debug logging for the IPsec feature of Cisco IOS XE Software could allow an authenticated, local attacker to display sensitive IPsec information in the system log file. The vulnerability is due to incorrect implementation of IPsec conditional, verbose debug logging that causes sensitive information to be writt
nvd
CVE-2001-0750P4MEDIUMCVSS 5.0v12.1\(2\)tv12.1\(3\)t2001-10-18
CVE-2001-0750 [MEDIUM] CVE-2001-0750: Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a conn Cisco IOS 12.1(2)T, 12.1(3)T allow remote attackers to cause a denial of service (reload) via a connection to TCP ports 3100-3999, 5100-5999, 7100-7999 and 10100-10999.
nvd
CVE-1999-0162P4MEDIUMCVSS 5.0v11.21998-09-01
CVE-1999-0162 [MEDIUM] CVE-1999-0162: The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering. The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering.
nvd
CVE-2002-2052P4MEDIUMCVSS 5.0v12.1\(6.5\)2002-12-31
CVE-2002-2052 [MEDIUM] CVE-2002-2052: Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cau Cisco 2611 router running IOS 12.1(6.5), possibly an interim release, allows remote attackers to cause a denial of service via port scans such as (1) scanning all ports on a single host and (2) scanning a network of hosts for a single open port through the router. NOTE: the vendor could not reproduce this issue, saying that the original reporter was using an
nvd
CVE-2002-2053P4MEDIUMCVSS 5.0v12.12002-12-31
CVE-2002-2053 [MEDIUM] CVE-2002-2053: The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using The design of the Hot Standby Routing Protocol (HSRP), as implemented on Cisco IOS 12.1, when using IRPAS, allows remote attackers to cause a denial of service (CPU consumption) via a router with the same IP address as the interface on which HSRP is running, which causes a loop.
nvd