Showing 15 vulnerabilities on this page for IOS Software

Signals CISA KEV Ransomware Nuclei
Cisco vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cisco IOS Software Denial-of-Service Vulnerability

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

CWE-399Mar 28, 2018
CVSS6.8v3.1EPSS4.97%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Resource Management Errors Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial of service (DoS) condition, aka a GET MIB Object ID Denial of Service Vulnerability. The vulnerability is due to a condition that could occur when the affected software processes an SNMP read request that contains a request for the ciscoFlashMIB object ID (OID). An attacker could trigg

CWE-399Mar 28, 2018
CVSS6.3v3.1EPSS4.67%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Denial-of-Service Vulnerability

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.

CWE-399Mar 28, 2018
CVSS6.8v3.1EPSS4.97%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device

CWE-399Mar 28, 2018
CVSS7.5v3.1EPSS7.12%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to the improper parsing of ingress PN-DCP Identify Request packets destined to an affected device. An attacker could exploit this vulnerability by sending a crafted PN-DCP Identify Request packet to an affe

CWE-20Sep 28, 2017
CVSS7.5v3.1EPSS7.13%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow t

CWE-399Sep 28, 2017
CVSS6.5v3.1EPSS2.17%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful

CWE-20Sep 28, 2017
CVSS7.5v3.1EPSS7.13%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful

CWE-20Sep 28, 2017
CVSS7.5v3.1EPSS7.13%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS

CWE-399Sep 28, 2017
CVSS7.5v3.1EPSS7.13%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are du

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS7.16%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Improper Input Validation

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.

CWE-20May 29, 2016
CVSS7.5v3.0EPSS3.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Cross-Site Request Forgery Vulnerability

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

CWE-352Sep 18, 2008
CVSS4.3v3.1EPSS33%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Denial-of-Service Vulnerability

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port.

CWE-400Feb 13, 2005
CVSS5.9v3.1EPSS4.71%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software Improper Authentication

HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.

CWE-287Mar 9, 20021 related artifact
CVSS9.3v2.0EPSS68.5%PoCs5SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cisco IOS HTTP Server '?/' String Vulnerability

The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a "?/" string.

Jan 22, 2001
CVSS5.0v2.0EPSS4.3%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX