cbcvebase.

Cisco iOS vulnerabilities

582 known vulnerabilities affecting cisco/ios.

Total CVEs
582
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH328MEDIUM212LOW11

Vulnerabilities

Page 7 of 30
CVE-2019-12655P3HIGHCVSS 7.5≥ 3.16.8s, < 16.3.8≥ 16.10.1, < 16.11.1+4 more2019-09-25
CVE-2019-12655 [HIGH] CWE-20 CVE-2019-12655: A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Tra A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT IPv6 to IPv4 (NAT64), and the Zone-Based Policy Firewall (ZBFW) in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a buffer overflow that occurs
nvd
CVE-2019-1748P3HIGHCVSS 7.4v12.0\(1\)v12.0\(1\)t+747 more2019-03-28
CVE-2019-1748 [HIGH] CWE-295 CVE-2019-1748: A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS X A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability exists because the affected software insufficiently validates certificates. An attacker could exploit this vulnerability by supplyi
nvd
CVE-2024-20311P3HIGHCVSS 7.5v15.1\(1\)syv15.1\(1\)sy1+778 more2024-03-27
CVE-2024-20311 [HIGH] CWE-674 CVE-2024-20311: A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to
nvd
CVE-2024-20308P3HIGHCVSS 7.5v12.4\(22\)mdv12.4\(22\)md1+1260 more2024-03-27
CVE-2024-20308 [HIGH] CWE-787 CVE-2024-20308: A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software coul A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading. This vulnerability exists because crafted, fragmented IKEv1 packets are not properly reassembled. An attacker could exploit this vulnerabil
nvd
CVE-2009-2865P3HIGHCVSS 7.6v12.4xwv12.4xy+2 more2009-09-28
CVE-2009-2865 [HIGH] CWE-119 CVE-2009-2865: Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communi Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
nvd
CVE-2017-3857P3HIGHCVSS 7.5≥ 12.0, ≤ 12.4≥ 15.0, ≤ 15.62017-03-22
CVE-2017-3857 [HIGH] CWE-399 CVE-2017-3857: A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 through 15.6) and Cisco IOS XE (3.1 through 3.18) could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient validation of L2TP packets. An attacker could exploit this vul
nvd
CVE-2019-12669P3HIGHCVSS 7.5v15.2\(3\)ev15.2\(3\)e5+1 more2019-09-25
CVE-2019-12669 [HIGH] CWE-20 CVE-2019-12669: A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Software, could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of a malformed packet. An attacker could exploit this vulnerability
nvd
CVE-2019-12656P3HIGHCVSS 7.5v1.6.0.0v1.8.02019-09-25
CVE-2019-12656 [HIGH] CWE-20 CVE-2019-12656: A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauth A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote attacker to cause the IOx web server to stop processing HTTPS requests, resulting in a denial of service (DoS) condition. The vulnerability is due to a Transport Layer Security (TLS) implementation issue. An attacker could exploit this
nvd
CVE-2009-0470P4MEDIUMCVSS 4.3PoCv12.4\(23\)2009-02-06
CVE-2009-0470 [MEDIUM] CVE-2009-0470: Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow r Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821.
nvd
CVE-2022-20920P3HIGHCVSS 7.7v12.2\(6\)i1v12.2\(58\)ex+1175 more2022-10-10
CVE-2022-20920 [HIGH] CWE-755 CVE-2022-20920: A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allo A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affecte
nvd
CVE-2025-20327P3HIGHCVSS 7.7v15.2(6)E2v15.2(7)E+27 more2025-09-24
CVE-2025-20327 [HIGH] CWE-1287 CVE-2025-20327: A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker wi A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input validation. An attacker could exploit this vulnerability by sending a crafted URL in an HTTP request. A successful exploit
nvd
CVE-2015-0635P3CRITICALCVSS 9.0v12.2\(33\)ird1v12.2\(33\)ire3+27 more2015-03-26
CVE-2015-0635 [CRITICAL] CWE-20 CVE-2015-0635: The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15 The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of serv
nvd
CVE-2005-3481P3CRITICALCVSS 9.3v12.0v12.0da+226 more2005-11-03
CVE-2005-3481 [CRITICAL] CVE-2005-3481: Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffe Cisco IOS 12.0 to 12.4 might allow remote attackers to execute arbitrary code via a heap-based buffer overflow in system timers. NOTE: this issue does not correspond to a specific vulnerability, rather a general weakness that only increases the feasibility of exploitation of any vulnerabilities that might exist. Such design-level weaknesses normally are not
nvd
CVE-2016-6380P3HIGHCVSS 8.1v12.0\(3\)tv12.0\(3\)t1+3203 more2016-10-05
CVE-2016-6380 [HIGH] CWE-20 CVE-2016-6380: The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 a The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.
nvd
CVE-2019-1752P3HIGHCVSS 7.5v15.0\(1\)mv15.0\(1\)m1+191 more2019-03-28
CVE-2019-1752 [HIGH] CWE-20 CVE-2019-1752: A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an A vulnerability in the ISDN functions of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload. The vulnerability is due to incorrect processing of specific values in the Q.931 information elements. An attacker could exploit this vulnerability by calling the affected device with specifi
nvd
CVE-2019-1738P3HIGHCVSS 7.5v15.1\(2\)sg8av15.1\(3\)svg3d+107 more2019-03-28
CVE-2019-1738 [HIGH] CWE-20 CVE-2019-1738: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit these vulnerabilities by sending crafted DNS packets throu
nvd
CVE-2019-1739P3HIGHCVSS 7.5v15.1\(2\)sg8av15.1\(3\)svg3d+107 more2019-03-28
CVE-2019-1739 [HIGH] CWE-20 CVE-2019-1739: A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software an A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to a parsing issue on DNS packets. An attacker could exploit this vulnerability by sending crafted DNS packets through
nvd
CVE-2019-1751P3HIGHCVSS 7.5v15.4\(1\)cg1v15.4\(1\)t+78 more2019-03-28
CVE-2019-1751 [HIGH] CWE-20 CVE-2019-1751: A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could A vulnerability in the Network Address Translation 64 (NAT64) functions of Cisco IOS Software could allow an unauthenticated, remote attacker to cause either an interface queue wedge or a device reload. The vulnerability is due to the incorrect handling of certain IPv4 packet streams that are sent through the device. An attacker could exploit this vulnera
nvd
CVE-2020-3200P3HIGHCVSS 7.7v12.2\(6\)i1v12.2\(58\)ex+907 more2020-06-03
CVE-2020-3200 [HIGH] CWE-371 CVE-2020-3200: A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Softwar A vulnerability in the Secure Shell (SSH) server code of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. The vulnerability is due to an internal state not being represented correctly in the SSH state machine, which leads to an unexpected behavior. An attacker could exploit
nvd
CVE-2020-3235P3HIGHCVSS 7.7v12.2\(52\)sgv12.2\(53\)sg1+80 more2020-06-03
CVE-2020-3235 [HIGH] CWE-118 CVE-2020-3235: A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient input validation when the software processes specific SNMP object
nvd