Showing 22 vulnerabilities on this page for IOS and IOS XE Software

Signals CISA KEV Ransomware Nuclei
Cisco vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of service (DoS) condition on an affected device that is running Cisco IOS Software or Cisco IOS XE Software. To cause the DoS, the attacker must have the SNMPv2c or earlier read-only community string or valid SNMPv3 user credentials. An authenticated, remote attacker

CWE-121Sep 24, 2025
CVSS7.7v3.1EPSS38.8%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute arbitrary code on an affected device or cause the device to crash. This vulnerability is due to insufficient validation of attributes in the Group Domain of Interpretation (GDOI) and G-IKEv2 protocols of the GET VPN feature. An attacker could

CWE-787Sep 27, 2023
CVSS6.6v3.1EPSS2.34%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of option 82 information that it receives in DHCP Version 4 (DHCPv4) packets from DHCP relay agents. An attacker could exploit this vulnerability by sending

CWE-20CWE-787Mar 28, 2018
CVSS8.6v3.1EPSS7.87%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of specific IKEv1 packets. An attacker could exploit this vulnerability by sending crafted IKEv1 packets to an affected device during an IKE negotiation. A successful explo

CWE-20Mar 28, 2018
CVSS7.5v3.1EPSS6.92%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers.

CWE-20Mar 28, 2018
CVSS8.6v3.1EPSS7.66%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. The vulnerability is due to incorrect bounds checking of certain values in packets that are destined for UDP port 18999 of an affected device. An attacker could exploit this vulnerability by sending malicious packets to an affected device. When the

CWE-119Mar 28, 2018
CVSS9.8v3.1EPSS14.3%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause a

CVSS8.6v3.1EPSS7.24%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a S

CWE-20CWE-399Mar 28, 2018
CVSS7.5v3.1EPSS8.2%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition, or to execute arbitrary code on an affected device. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted Smart Install message to an affected device on TCP port 4786. A successful exploit c

CWE-20CWE-787Mar 28, 20181 related artifact
CVSS9.8v3.1EPSS99.5%PoCs2SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by s

CWE-119CWE-20Sep 28, 2017
CVSS9.8v3.1EPSS13.9%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected dev

CWE-399CWE-400Sep 28, 2017
CVSS7.5v3.1EPSS7.13%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a denial of service (DoS) condition. The vulnerability is due to Cisco IOS Software application changes that create UDP sockets and leave the sockets idle without closing them. An attacker could exploit this vulnerability by sending UDP pack

CWE-399CWE-404Sep 7, 2017
CVSS7.5v3.1EPSS6.04%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.

Aug 7, 2017
CVSS6.5v3.1EPSS2.14%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are du

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS10.5%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are du

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS10.5%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS21.4%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are du

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS10.8%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS42.6%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are du

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS70.6%PoCs2SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.  The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or

CWE-119Jul 17, 2017
CVSS8.8v3.1EPSS10.5%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Cisco IOS and IOS XE Remote Code Execution Vulnerability

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. The Cluster Management Protocol utilizes Telnet internally as a signaling and command protocol between cluster members. The vulnerability is due to the combination of two factors: (1) the failure to restrict the use of CMP-specific Telnet opti

CWE-20Mar 17, 20171 related artifact
CVSS9.8v3.1EPSS99%PoCs8SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

CWE-200Sep 19, 2016
CVSS7.5v3.1EPSS87.3%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX