Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 7 of 30
CVE-2019-12655P3HIGHCVSS 7.5≥ 3.16.8s, < 16.3.8≥ 16.10.1, < 16.11.1+4 more2019-09-25
CVE-2019-12655 [HIGH] CWE-20 CVE-2019-12655: A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Tra
A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT IPv6 to IPv4 (NAT64), and the Zone-Based Policy Firewall (ZBFW) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a buffer overflow that occurs
nvd
CVE-2016-6422P3HIGHCVSS 7.5v12.2\(33\)sxj92016-10-06
CVE-2016-6422 [HIGH] CWE-20 CVE-2016-6422: Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles
Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices mishandles certain operators, flags, and keywords in TCAM share ACLs, which allows remote attackers to bypass intended access restrictions by sending packets that should have been recognized by a filter, aka Bug ID CSCuy64806.
nvd
CVE-2019-1748P3HIGHCVSS 7.4v12.0\(1\)v12.0\(1\)t+747 more2019-03-28
CVE-2019-1748 [HIGH] CWE-295 CVE-2019-1748: A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS X
A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplyi
nvd
CVE-2024-20311P3HIGHCVSS 7.5v15.1\(1\)syv15.1\(1\)sy1+778 more2024-03-27
CVE-2024-20311 [HIGH] CWE-674 CVE-2024-20311: A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to
nvd
CVE-2024-20308P3HIGHCVSS 7.5v12.4\(22\)mdv12.4\(22\)md1+1260 more2024-03-27
CVE-2024-20308 [HIGH] CWE-787 CVE-2024-20308: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul
A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading.
This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabil
nvd
CVE-2017-3857P3HIGHCVSS 7.5≥ 12.0, ≤ 12.4≥ 15.0, ≤ 15.62017-03-22
CVE-2017-3857 [HIGH] CWE-399 CVE-2017-3857: A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 through 15.6) and Cisco IOS XE (3.1 through 3.18) could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient validation of L2TP packets. An attacker could exploit this vul
nvd
CVE-2019-1738P3HIGHCVSS 7.5v15.1\(2\)sg8av15.1\(3\)svg3d+107 more2019-03-28
CVE-2019-1738 [HIGH] CWE-20 CVE-2019-1738: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit these vulnerabilities by sending crafted DNS packets throu
nvd
CVE-2019-1739P3HIGHCVSS 7.5v15.1\(2\)sg8av15.1\(3\)svg3d+107 more2019-03-28
CVE-2019-1739 [HIGH] CWE-20 CVE-2019-1739: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an
A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through
nvd
CVE-2019-12669P3HIGHCVSS 7.5v15.2\(3\)ev15.2\(3\)e5+1 more2019-09-25
CVE-2019-12669 [HIGH] CWE-20 CVE-2019-12669: A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within
A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Software, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of a malformed packet. An attacker could exploit this vulnerability
nvd
CVE-2019-12656P3HIGHCVSS 7.5v1.6.0.0v1.8.02019-09-25
CVE-2019-12656 [HIGH] CWE-20 CVE-2019-12656: A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauth
A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this
nvd
CVE-2009-0470P4MEDIUMCVSS 4.3PoCv12.4\(23\)2009-02-06
CVE-2009-0470 [MEDIUM] CVE-2009-0470: Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow r
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.
nvd
CVE-2022-20920P3HIGHCVSS 7.7v12.2\(6\)i1v12.2\(58\)ex+1175 more2022-10-10
CVE-2022-20920 [HIGH] CWE-755 CVE-2022-20920: A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allo
A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affecte
nvd
CVE-2008-4609P3HIGHCVSS 7.1v4.1v4.1.1+1455 more2008-10-20
CVE-2008-4609 [HIGH] CWE-16 CVE-2008-4609: The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cis
The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.
nvd
CVE-2015-0635P3CRITICALCVSS 9.0v12.2\(33\)ird1v12.2\(33\)ire3+27 more2015-03-26
CVE-2015-0635 [CRITICAL] CWE-20 CVE-2015-0635: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of serv
nvd
CVE-2005-3481P3CRITICALCVSS 9.3v12.0v12.0da+226 more2005-11-03
CVE-2005-3481 [CRITICAL] CVE-2005-3481: Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffe
Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffer overflow in system timers. NOTE: this issue does not correspond to a specific vulnerability, rather a general weakness that only increases the feasibility of exploitation of any vulnerabilities that might exist. Such design-level weaknesses normally are not
nvd
CVE-2005-2105P3HIGHCVSS 7.5v12.2\(2\)xrv12.2\(4\)xr+90 more2005-07-05
CVE-2005-2105 [HIGH] CVE-2005-2105: Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Ac
Cisco IOS 12.2T through 12.4 allows remote attackers to bypass Authentication, Authorization, and Accounting (AAA) RADIUS authentication, if the fallback method is set to none, via a long username.
nvd
CVE-2019-1752P3HIGHCVSS 7.5v15.0\(1\)mv15.0\(1\)m1+191 more2019-03-28
CVE-2019-1752 [HIGH] CWE-20 CVE-2019-1752: A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an
A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of specific values in the Q.931 information elements. An attacker could exploit this vulnerability by calling the affected device with specifi
nvd
CVE-2019-1751P3HIGHCVSS 7.5v15.4\(1\)cg1v15.4\(1\)t+78 more2019-03-28
CVE-2019-1751 [HIGH] CWE-20 CVE-2019-1751: A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could
A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could allow an unauthenticated, remote attacker to cause either an interface queue wedge or a device reload. The vulnerability is due to the incorrect handling of certain IPv4 packet streams that are sent through the device. An attacker could exploit this vulnera
nvd
CVE-2020-3200P3HIGHCVSS 7.7v12.2\(6\)i1v12.2\(58\)ex+907 more2020-06-03
CVE-2020-3200 [HIGH] CWE-371 CVE-2020-3200: A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Softwar
A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. The vulnerability is due to an internal state not being represented correctly in the SSH state machine, which leads to an unexpected behavior. An attacker could exploit
nvd
CVE-2020-3235P3HIGHCVSS 7.7v12.2\(52\)sgv12.2\(53\)sg1+80 more2020-06-03
CVE-2020-3235 [HIGH] CWE-118 CVE-2020-3235: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the software processes specific SNMP object
nvd