cbcvebase.

Cisco iOS vulnerabilities

581 known vulnerabilities affecting cisco/ios.

Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11

Vulnerabilities

Page 3 of 30
CVE-2016-1409P2HIGHCVSS 7.5Exploitedv12.0\(1\)v12.0\(1\)db+4357 more2016-05-29
CVE-2016-1409 [HIGH] CWE-20 CVE-2016-1409: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3. The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
nvd
CVE-2007-4286P2CRITICALCVSS 9.3PoCv12.0v12.1+3 more2007-08-09
CVE-2007-4286 [CRITICAL] CWE-119 CVE-2007-4286: Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 1 Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (restart) and execute arbitrary code via a crafted NHRP packet.
nvd
CVE-2002-1359P3CRITICALCVSS 10.0PoCv12.0sv12.0st+6 more2002-12-23
CVE-2002-1359 [CRITICAL] CWE-20 CVE-2002-1359: Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may al Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.
nvd
CVE-2007-2586P2CRITICALCVSS 9.3PoCv12.0\(1\)tv12.0\(1\)t1+378 more2007-05-10
CVE-2007-2586 [CRITICAL] CWE-863 CVE-2007-2586: The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allo The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
nvd
CVE-2007-5381P3CRITICALCVSS 9.3PoCv10.3v10.3\(3.3\)+1427 more2007-10-12
CVE-2007-5381 [CRITICAL] CWE-119 CVE-2007-5381: Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4 Stack-based buffer overflow in the Line Printer Daemon (LPD) in Cisco IOS before 12.2(18)SXF11, 12.4(16a), and 12.4(2)T6 allow remote attackers to execute arbitrary code by setting a long hostname on the target system, then causing an error message to be printed, as demonstrated by a telnet session to the LPD from a source port other than 515.
nvd
CVE-2019-12650P2HIGHCVSS 8.8v16.11.12019-09-25
CVE-2019-12650 [HIGH] CWE-77 CVE-2019-12650: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2005-2841P3HIGHCVSS 7.5PoCv12.2zhv12.2zl+4 more2005-09-08
CVE-2005-2841 [HIGH] CVE-2005-2841: Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 and 12.3T, and 12.4 and 12.4T allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted user authentication credentials.
nvd
CVE-2020-3258P2CRITICALCVSS 9.8v15.8\(3\)m2v15.8\(9\)+1 more2020-06-03
CVE-2020-3258 [CRITICAL] CWE-119 CVE-2020-3258: Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash an
nvd
CVE-2020-3198P2CRITICALCVSS 9.8v12.2\(60\)ez16v15.0\(2\)sg11a+81 more2020-06-03
CVE-2020-3198 [CRITICAL] CWE-119 CVE-2020-3198: Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash an
nvd
CVE-2003-0647P3HIGHCVSS 7.5PoC≤ 12.22003-08-27
CVE-2003-0647 [HIGH] CVE-2003-0647: Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via an extremely long (2GB) HTTP GET request.
nvd
CVE-2003-0567P3HIGHCVSS 7.8PoCv11.0v11.1+167 more2003-08-18
CVE-2003-0567 [HIGH] CWE-20 CVE-2003-0567: Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic b Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a particular sequence of IPv4 packets to an interface on the device, causing the input queue on that interface to be marked as full.
nvd
CVE-2019-12648P3HIGHCVSS 8.8v15.7\(3\)m32019-09-25
CVE-2019-12648 [HIGH] CWE-284 CVE-2019-12648: A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticat A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker to gain unauthorized access to the Guest Operating System (Guest OS) running on an affected device. The vulnerability is due to incorrect role-based access control (RBAC) evaluation when a low-privileged user requests access to a Gue
nvd
CVE-2003-0100P3HIGHCVSS 7.5PoCv11.1v11.1\(7\)aa+219 more2003-03-03
CVE-2003-0100 [HIGH] CVE-2003-0100: Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service a Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote attackers to cause a denial of service and possibly execute commands via a large number of OSPF neighbor announcements.
nvd
CVE-2025-20160P3HIGHCVSS 8.1v15.2(6)E1v15.2(4)E6+122 more2025-09-24
CVE-2025-20160 [HIGH] CWE-287 CVE-2025-20160: A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This vulnerability exists because the system does not properly check whether the required TACACS+ shared secret is configured. A machine-in-the-mi
nvd
CVE-2019-12651P3HIGHCVSS 8.8v16.11.12019-09-25
CVE-2019-12651 [HIGH] CWE-77 CVE-2019-12651: Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could all Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2002-0813P4HIGHCVSS 7.1PoCv11.1v11.2+1 more2002-08-12
CVE-2002-0813 [HIGH] CWE-119 CVE-2002-0813: Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows re Heap-based buffer overflow in the TFTP server capability in Cisco IOS 11.1, 11.2, and 11.3 allows remote attackers to cause a denial of service (reset) or modify configuration via a long filename.
nvd
CVE-2023-20186P3CRITICALCVSS 9.1v12.2\(58\)exv12.2\(58\)ey+1227 more2023-09-27
CVE-2023-20186 [CRITICAL] CWE-285 CVE-2023-20186: A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Soft A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an affected device using the Secure Copy Protocol (SCP). This vulnerability is due to incorrect
nvd
CVE-2006-4950P3CRITICALCVSS 10.0≤ 12.3v12.3\(1a\)+226 more2006-09-23
CVE-2006-4950 [CRITICAL] CVE-2006-4950: Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrat Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, which allows remote attackers to gain read-write access via a hard-coded cable-docsis community string a
nvd
CVE-2001-0288P4HIGHCVSS 7.5PoC≤ 12.12001-05-03
CVE-2001-0288 [HIGH] CVE-2001-0288: Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Num Cisco switches and routers running IOS 12.1 and earlier produce predictable TCP Initial Sequence Numbers (ISNs), which allows remote attackers to spoof or hijack TCP connections.
nvd
CVE-2007-4430P4MEDIUMCVSS 5.0PoCv10.0v10.3+8 more2007-08-20
CVE-2007-4430 [MEDIUM] CWE-20 CVE-2007-4430: Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service (device restart and BGP routing table rebuild) via certain regular expressions in a "show ip bgp regexp" command. NOTE: unauthenticated remote attacks are possible in environments with anonymous telnet and Looking Glass access.
nvd