cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 29 of 30
CVE-2003-0305P4MEDIUMCVSS 5.0v12.0\(15\)sv12.0\(15\)sc+46 more2003-06-09
CVE-2003-0305 [MEDIUM] CVE-2003-0305: The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967.
nvd
CVE-1999-0445P4MEDIUMCVSS 5.0v12.0v12.0\(1\)w+10 more1999-04-01
CVE-1999-0445 [MEDIUM] CVE-1999-0445: In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by in In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters.
nvd
CVE-1999-0230P4MEDIUMCVSS 5.0v4.1v4.1.1+1 more1997-12-15
CVE-1999-0230 [MEDIUM] CVE-1999-0230: Buffer overflow in Cisco 7xx routers through the telnet service. Buffer overflow in Cisco 7xx routers through the telnet service.
nvd
CVE-2012-4638P4MEDIUMCVSS 4.9v15.12014-04-23
CVE-2012-4638 [MEDIUM] CVE-2012-4638: Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establ Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establishing an outbound SSH session, aka Bug ID CSCto00318.
nvd
CVE-2006-0485P4MEDIUMCVSS 4.6v12.0tv12.0xh+128 more2006-02-01
CVE-2006-0485 [MEDIUM] CVE-2006-0485: The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain o The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local users to execute IOS EXEC commands that were prohibited via the AAA configuration, aka Bug ID CSCeh7304
nvd
CVE-2012-5427P4MEDIUMCVSS 4.0≤ 15.3\(2\)sv15.32014-04-23
CVE-2012-5427 [MEDIUM] CWE-20 CVE-2012-5427: Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated use Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518.
nvd
CVE-2010-4685P4MEDIUMCVSS 4.0fixed in 15.0\(1\)xa12011-01-07
CVE-2010-4685 [MEDIUM] CWE-295 CVE-2010-4685: Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta79031.
nvd
CVE-2006-4650P4LOWCVSS 2.6v12.0v12.1+1 more2006-09-09
CVE-2006-4650 [LOW] CVE-2006-4650: Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are m Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memory locations, which allows remote attackers to inject crafted packets into the routing queue, possibly bypassi
nvd
CVE-2005-3921P4LOWCVSS 2.6≤ 12.3v12.3\(1a\)+223 more2005-11-30
CVE-2005-3921 [LOW] CVE-2005-3921: Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote atta Cross-site scripting (XSS) vulnerability in Cisco IOS Web Server for IOS 12.0(2a) allows remote attackers to inject arbitrary web script or HTML by (1) packets containing HTML that an administrator views via an HTTP interface to the contents of memory buffers, as demonstrated by the URI /level/15/exec/-/buffers/assigned/dump; or (2) sending the router Cisco Disc
nvd
CVE-2011-3289P4LOWCVSS 3.6v12.4v15.0+2 more2012-05-02
CVE-2011-3289 [LOW] CWE-264 CVE-2011-3289: Cisco IOS 12.4 and 15.0 through 15.2 allows physically proximate attackers to bypass the No Service Cisco IOS 12.4 and 15.0 through 15.2 allows physically proximate attackers to bypass the No Service Password-Recovery feature and read the start-up configuration via unspecified vectors, aka Bug ID CSCtr97640.
nvd
CVE-2006-0486P4MEDIUMCVSS 4.6v12.2\(25\)sv12.3t+1 more2006-02-01
CVE-2006-0486 [MEDIUM] CVE-2006-0486: Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T Certain Cisco IOS releases in 12.2S based trains with maintenance release number 25 and later, 12.3T based trains, and 12.4 based trains reuse a Tcl Shell process across login sessions of different local users on the same terminal if the first user does not use tclquit before exiting, which may cause subsequent local users to execute unintended commands or by
nvd
CVE-2012-5037P4MEDIUMCVSS 4.6≤ 15.12014-04-23
CVE-2012-5037 [MEDIUM] CWE-264 CVE-2012-5037: The ACL implementation in Cisco IOS before 15.1(1)SY on Catalyst 6500 and 7600 devices allows local The ACL implementation in Cisco IOS before 15.1(1)SY on Catalyst 6500 and 7600 devices allows local users to cause a denial of service (device reload) via a "no object-group" command followed by an object-group command, aka Bug ID CSCts16133.
nvd
CVE-2005-4826P4MEDIUMCVSS 6.1v12.1\(22\)ea32005-12-31
CVE-2005-4826 [MEDIUM] CVE-2005-4826: Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Ca Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (device reboot) via a crafted Subset-Advert message packet, a different issue than CVE-2006-4774, CVE-2006-4775, and CVE-2006-4776.
nvd
CVE-2012-3923P4LOWCVSS 3.5v12.4v15.0+2 more2012-09-16
CVE-2012-3923 [LOW] CVE-2012-3923: The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does no The SSLVPN implementation in Cisco IOS 12.4, 15.0, 15.1, and 15.2, when DTLS is not enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCte41827.
nvd
CVE-1999-0157P4MEDIUMCVSS 5.0v11.2pv11.3t+2 more1998-08-18
CVE-1999-0157 [MEDIUM] CVE-1999-0157: Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service. Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.
nvd
CVE-2012-3924P4LOWCVSS 3.5v15.1v15.22012-09-16
CVE-2012-3924 [LOW] CVE-2012-3924: The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle The SSLVPN implementation in Cisco IOS 15.1 and 15.2, when DTLS is enabled, does not properly handle certain outbound ACL configurations, which allows remote authenticated users to cause a denial of service (device crash) via a session involving a PPP over ATM (PPPoA) interface, aka Bug ID CSCty97961.
nvd
CVE-2012-1344P4LOWCVSS 3.5v15.1v15.22012-08-06
CVE-2012-1344 [LOW] CWE-119 CVE-2012-1344: Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr86328.
nvd
CVE-2000-0368P4LOWCVSS 2.1≤ 9.12001-03-12
CVE-2000-0368 [LOW] CWE-200 CVE-2000-0368: Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions Classic Cisco IOS 9.1 and later allows attackers with access to the login prompt to obtain portions of the command history of previous users, which may allow the attacker to access sensitive data.
nvd
CVE-2015-6375P4LOWCVSS 2.1v15.2\(2\)e32015-11-21
CVE-2015-6375 [LOW] CWE-200 CVE-2015-6375: The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allow The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010.
nvd
CVE-1999-0159P4LOWCVSS 3.5v9.1v11.0\(20.3\)+14 more1998-08-12
CVE-1999-0159 [LOW] CWE-400 CVE-1999-0159: Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (su Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases.
nvd
Cisco iOS vulnerabilities | cvebase