Cisco iOS vulnerabilities
581 known vulnerabilities affecting cisco/ios.
Total CVEs
581
CISA KEV
37
actively exploited
Public exploits
28
Exploited in wild
41
Severity breakdown
CRITICAL31HIGH327MEDIUM212LOW11
Vulnerabilities
Page 8 of 30
CVE-2021-1460P3HIGHCVSS 7.5fixed in 15.9\(3\)m32021-03-24
CVE-2021-1460 [HIGH] CWE-400 CVE-2021-1460: A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services R
A vulnerability in the Cisco IOx Application Framework of Cisco 809 Industrial Integrated Services Routers (Industrial ISRs), Cisco 829 Industrial ISRs, Cisco CGR 1000 Compute Module, and Cisco IC3000 Industrial Compute Gateway could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulner
nvd
CVE-2023-20080P3HIGHCVSS 7.5v12.2\(6\)i1v15.1\(2\)sg+485 more2023-03-23
CVE-2023-20080 [HIGH] CWE-129 CVE-2023-20080: A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS X
A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation of data boundaries. An attacker could exploit this vulnerability by sending crafted DHCPv6 me
nvd
CVE-2016-6380P3HIGHCVSS 8.1v12.0\(3\)tv12.0\(3\)t1+3203 more2016-10-05
CVE-2016-6380 [HIGH] CWE-20 CVE-2016-6380: The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 a
The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.
nvd
CVE-2001-1097P4MEDIUMCVSS 5.0PoCv12.0v12.0\(1\)+8 more2001-07-24
CVE-2001-1097 [MEDIUM] CVE-2001-1097: Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denia
Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.
nvd
CVE-2021-34699P3HIGHCVSS 7.7v12.2\(6\)i1v15.0\(1\)sy+513 more2021-09-23
CVE-2021-34699 [HIGH] CWE-435 CVE-2021-34699: A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an aut
A vulnerability in the TrustSec CLI parser of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to an improper interaction between the web UI and the CLI parser. An attacker could exploit this vulnerability by requesting a particular CLI command to be run
nvd
CVE-2006-4776P3HIGHCVSS 7.5v12.1\(19\)2006-09-14
CVE-2006-4776 [HIGH] CWE-119 CVE-2006-4776: Heap-based buffer overflow in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows
Heap-based buffer overflow in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(19) allows remote attackers to execute arbitrary code via a long VLAN name in a VTP type 2 summary advertisement.
nvd
CVE-2021-1392P3HIGHCVSS 7.8v15.0\(1\)eyv15.0\(1\)ey1+183 more2021-03-24
CVE-2021-1392 [HIGH] CWE-522 CVE-2021-1392: A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an
A vulnerability in the CLI command permissions of Cisco IOS and Cisco IOS XE Software could allow an authenticated, local attacker to retrieve the password for Common Industrial Protocol (CIP) and then remotely configure the device as an administrative user. This vulnerability exists because incorrect permissions are associated with the show cip securit
nvd
CVE-2019-12665P3HIGHCVSS 7.4v15.6\(2\)tvfd-1.5.02019-09-25
CVE-2019-12665 [HIGH] CWE-399 CVE-2019-12665: A vulnerability in the HTTP client feature of Cisco IOS and IOS XE Software could allow an unauthent
A vulnerability in the HTTP client feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to read and modify data that should normally have been sent via an encrypted channel. The vulnerability is due to TCP port information not being considered when matching new requests to existing, persistent HTTP connections. An a
nvd
CVE-2015-6289P3HIGHCVSS 7.5v15.5\(3\)m2016-06-23
CVE-2015-6289 [HIGH] CWE-399 CVE-2015-6289: Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attac
Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets on the SSH port, aka Bug ID CSCuu13476.
nvd
CVE-2012-0382P3HIGHCVSS 7.5v12.0v12.2+753 more2012-03-29
CVE-2012-0382 [HIGH] CWE-400 CVE-2012-0382: The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4,
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug I
nvd
CVE-2016-1384P3HIGHCVSS 7.5v15.1\(1\)sv15.1\(1\)s1+31 more2016-04-20
CVE-2016-1384 [HIGH] CWE-264 CVE-2016-1384: The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attacker
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
nvd
CVE-2016-6382P3HIGHCVSS 7.5v15.2\(1\)syv15.2\(1\)sy0a+105 more2016-10-05
CVE-2016-6382 [HIGH] CWE-399 CVE-2016-6382: Cisco IOS 15.2 through 15.6 and IOS XE 3.6 through 3.17 and 16.1 allow remote attackers to cause a d
Cisco IOS 15.2 through 15.6 and IOS XE 3.6 through 3.17 and 16.1 allow remote attackers to cause a denial of service (device restart) via a malformed IPv6 Protocol Independent Multicast (PIM) register packet, aka Bug ID CSCuy16399.
nvd
CVE-2015-0646P3HIGHCVSS 7.8v12.2v12.4+5 more2015-03-26
CVE-2015-0646 [HIGH] CWE-399 CVE-2015-0646: Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3
Memory leak in the TCP input module in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.3.xXO, 3.5.xE, 3.6.xE, 3.8.xS through 3.10.xS before 3.10.5S, and 3.11.xS and 3.12.xS before 3.12.3S allows remote attackers to cause a denial of service (memory consumption or device reload) by sending crafted TCP packets over (1) IPv4 or (2) IPv6, aka
nvd
CVE-2011-0935P3CRITICALCVSS 10.0v15.0v15.12011-04-14
CVE-2011-0935 [CRITICAL] CVE-2011-0935: The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain publi
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass authentication and have unspecified other impact by leveraging an IKE peer relationship in which a key was previously valid but later revoked, aka Bug ID CSCth82164, a different vulnerability than CVE-2010-4685.
nvd
CVE-2015-6279P3HIGHCVSS 7.8v12.2\(50\)syv12.2\(50\)sy1+90 more2015-09-28
CVE-2015-6279 [HIGH] CWE-20 CVE-2015-6279: The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 1
The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE, 3.3XO, 3.4SG, 3.5E, and 3.6E before 3.6.3E; 3.7E before 3.7.2E; 3.9S and 3.10S before 3.10.6S; 3.11S before 3.11.4S; 3.12S and 3.13S before 3.13.3S; and 3.14S before 3.14.2S allows remote attackers to caus
nvd
CVE-2016-1399P3HIGHCVSS 7.5v15.2\(2\)ebv15.2\(2\)eb1+4 more2016-05-14
CVE-2016-1399 [HIGH] CWE-399 CVE-2016-1399: The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Ind
The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 4000 devices and 15.2(2)EB and 15.2(2)EB1 on Industrial Ethernet 5000 devices allows remote attackers to cause a denial of service (packet data corruption) via crafted IPv4 ICMP packets, aka Bug ID CSCuy13431.
nvd
CVE-2006-3291P3CRITICALCVSS 9.3v12.3\(8\)jav12.3\(8\)ja12006-06-28
CVE-2006-3291 [CRITICAL] CWE-16 CVE-2006-3291: The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point
The web interface on Cisco IOS 12.3(8)JA and 12.3(8)JA1, as used on the Cisco Wireless Access Point and Wireless Bridge, reconfigures itself when it is changed to use the "Local User List Only (Individual Passwords)" setting, which removes all security and password configurations and allows remote attackers to access the system.
nvd
CVE-2021-1620P3HIGHCVSS 7.7v12.2\(6\)i1v15.1\(3\)svr1+410 more2021-09-23
CVE-2021-1620 [HIGH] CWE-563 CVE-2021-1620: A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) support for the AutoReconnect feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to exhaust the free IP addresses from the assigned local pool. This vulnerability occurs because the code does not release the allocated IP address under certai
nvd
CVE-2005-1057P3HIGHCVSS 7.5v12.2tv12.3+1 more2005-05-02
CVE-2005-1057 [HIGH] CVE-2005-1057: Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows r
Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."
nvd
CVE-2016-6414P3HIGHCVSS 7.8v15.6\(1\)t12016-09-22
CVE-2016-6414 [HIGH] CWE-78 CVE-2016-6414: iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local use
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
nvd