Known vulnerabilities in Cisco IOS - page 3

Software: Cisco IOS
Software CPE: cpe:2.3:o:cisco_systems:cisco_ios:*:*:*:*:*:*:*:*
Total vulnerabilities: 87
Public exploits: 4
Known exploited (KEV): 18
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Cisco IOS Cisco IOS is affected by 87 known vulnerabilities: 2 critical, 18 high, 31 medium, 36 low Critical High Medium Low

Vulnerabilities (87)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU68873 - State Issues
CVE-2020-3200
CWE-371 Medium
No
No
ap-16.12.4.9, ap-16.12.4a, ap-17.1.1.30, ap-17.1.1t, ap-17.2.0.78, ap-17.2.1.4, ap-17.2.1, ap-17.3.0.42, ap-17.3.1, 008.005(161.102), 008.005(162.107), 008.005(164.000), 008.005(164.008), 8.5.171.0, 008.008(128.041), 008.008(130.000), 008.010(105.146), 008.010(112.102), 008.010(113.000), 008.010(118.084), 008.010(121.000), 008.010(128.055), 008.010(130.000), 15.0(02)SE13a, 15.1(2)SY16, 15.1(2)SY17, 15.2(2)E10a, 15.2(04)E10, 15.2(7b)E00b, 15.2(7)E2, 15.2(7)E3, 15.2(7)E4, 15.2(07.00.59i)E2, 15.2(07.00.87i)E2, 15.2(07.01.03s)E1, 15.2(07.01.62k)E1, 15.2(07.01.78i)E3, 15.2(07.02.00l)E4, 15.2(8)E, 15.3(03)JF12i, 15.3.3 JF14, 15.3(03)JI06, 15.3(03)JK01t, 15.3(03)JK02, 15.3(03)JK02a, 15.3(03)JK05, 15.3(03)JPI06a, 15.3(03)JPJ02t, 15.3(03)JPJ03, 15.3(03)JPJ06, 15.5(1)IA001.1211, 15.5(1)SY5, 15.5(1)SY6, 15.5(01.01.10)SY04, 15.5(3)M11, 15.5(3)S10a, 15.6(02)SP08, 15.6(02.01)SP09, 15.6(03)M08, 15.7(03)M06, 15.7(03.00q)M05, 15.8(03.00d)M03, 15.8(03)M04, 15.8(03.01s)M01, 15.9(3)M1, 16.3.10, 16.3.11, 16.6(6.82), 16.6.7, 16.6.7a, 16.6.8, 16.6.9, 16.6.10, 16.9(3.60), 16.9.4, 16.9.5, 16.9.6, 16.9.7, 16.9.8, 16.10.3, 16.12(0.141), 16.12.1, 16.12.1c, 16.12.1d, 16.12.1e, 16.12.1s, 16.12.1t, 16.12.1w, 16.12.1x, 16.12.1y, 16.12.1z, 16.12.1z1, 16.12.1z2, 16.12.1a, 16.12.1b, 16.12(1.2), 16.12.2, 16.12.2s, 16.12.2t, 16.12.2a, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 16.12.5 b, 16.12.6, 16.12.6a, 16.12.7, 17.1(0.35), 17.1.1, 17.1.1s, 17.1.1t, 17.1.1a, 17.1.2, 17.1.3, 17.2.1, 17.2.1v, 17.2.1a, 17.2.1r, 17.2.2, 17.2.3, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1z, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.3.4, 17.3.4c, 17.3.4a, 17.3.4b, 17.3.5, 17.3.5a, 17.4.1, 17.4.1a, 17.4.1b, 17.4.2, 17.5.1, 17.5.1a, 17.6.1, 17.6.1w, 17.6.1x, 17.6.1y, 17.6.1a, 17.6.2, 17.6.3, 17.6.3a, 17.7.1, 17.7.1a 01.11.2022 SB2020060371
SB2022110108
#VU56841 - Security Features
CVE-2021-34705
CWE-254 Medium
No
No
16.9.7, 16.12.6, 17.3.3, 17.3.4, 17.5.1, 17.6.1 23.09.2021 SB2021092312
#VU51788 - Resource exhaustion
CVE-2021-1460
CWE-400 Medium
No
No
15.9.3 M3 30.03.2021 SB2021033017
#VU51770 - Resource Management Errors
CVE-2021-1377
CWE-399 Medium
No
No
15.2(2)E10a, 15.2(4)E10b, 15.2(7)E4, 15.2(7.1.0p)E4, 15.2(8.0.6p)E, 15.2(8.0.13j)E, 15.5.1 SY7, 15.5.1.0.17 SY6, 15.7.3 M8, 15.8.3 M6, 15.8.3.0u M4, 15.9.3 M3, 15.9.3.0p M2, 16.3.5, 16.3.5c, 16.3.5a, 16.3.5b, 16.3.6, 16.3.7, 16.3.8, 16.3.9, 16.3.10, 16.3.11, 16.6.9, 16.7.1, 16.7.1a, 16.7.1b, 16.7.2, 16.7.3, 16.7.4, 16.8.1, 16.8.1c, 16.8.1d, 16.8.1e, 16.8.1s, 16.8.1a, 16.8.1b, 16.8.2, 16.8.3, 16.9.1, 16.9.1c, 16.9.1d, 16.9.1s, 16.9.1a, 16.9.1b, 16.9.2, 16.9.2s, 16.9.2a, 16.9.3, 16.9.3h, 16.9.3s, 16.9.3a, 16.9.4, 16.9.4c, 16.9.5, 16.9.5f, 16.9.6, 16.9.6.56, 16.9.7, 16.10.1, 16.10.1c, 16.10.1d, 16.10.1e, 16.10.1f, 16.10.1g, 16.10.1i, 16.10.1s, 16.10.1a, 16.10.1b, 16.10.2, 16.10.3, 16.11.1, 16.11.1c, 16.11.1s, 16.11.1a, 16.11.1b, 16.11.2, 16.12.1, 16.12.1c, 16.12.1s, 16.12.1t, 16.12.1w, 16.12.1x, 16.12.1y, 16.12.1z, 16.12.1a, 16.12.2, 16.12.2s, 16.12.2t, 16.12.2a, 16.12.3, 16.12.3s, 16.12.3a, 16.12.4, 16.12.4a, 16.12.4.40, 16.12.5, 16.12.5a, 17.1.1, 17.1.1s, 17.1.1t, 17.1.1a, 17.1.2, 17.1.3, 17.2.1, 17.2.1v, 17.2.1a, 17.2.1r, 17.2.1.126, 17.2.2, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.2.1, 17.3.3, 17.3.3a, 17.4.0.145, 17.4.1, 17.4.1a, 17.4.1b, 17.5.0.40 29.03.2021 SB2021032919
#VU51768 - Insufficiently Protected Credentials
CVE-2021-1392
CWE-522 Low
No
No
8.5.164.27, 8.5.171.0, 15.2(7)E4, 15.2(7.0.16j)E4, 15.2(7.1.0p)E4, 15.3.3 JF14, 16.12.4.40, 16.12.5, 16.12.5a, 17.1.3, 17.2.1.177, 17.3.0.188, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b 29.03.2021 SB2021032917
SB2021042150
#VU51765 - Active Debug Code
CVE-2021-1391
CWE-489 Low
No
No
15.2(7)E4, 15.2(7.1.0p)E4, 15.2(8.0.18p)E, 15.2(8.0.28j)E, 16.9.6.123, 16.9.7, 16.12.3.49, 16.12.4, 16.12.4a, 16.12.5, 16.12.5a, 17.1.3, 17.3.0.188, 17.3.1, 17.3.1w, 17.3.1x, 17.3.1a, 17.3.2, 17.3.2a, 17.3.3, 17.4.0.56, 17.4.1, 17.4.1a, 17.4.1b 29.03.2021 SB2021032914
#VU51731 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-1385
CWE-22 Low
No
No
15.8.3 M2, 15.9.3 M4 25.03.2021 SB2021032517
SB2022110109
#VU47109 - NULL Pointer Dereference
CVE-2020-3407
CWE-476 High
No
No
- 24.09.2020 SB2020092502
#VU47110 - Improper input validation
CVE-2020-3512
CWE-20 Medium
No
No
- 24.09.2020 SB2020092503
#VU47236 - Exposure of sensitive information to an unauthorized actor
CVE-2020-3477
CWE-200 Low
No
No
17.2.1, 17.2.1EFT, 17.2.2, 17.3.1, 17.3.1EFT, 17.3.1a, 17.3.2EFT 24.09.2020 SB2020100108
#VU24161 - Cross-Site Request Forgery (CSRF)
CVE-2019-16009
CWE-352 Low
No
No
16.1.1 09.01.2020 SB2020010912
#VU21352 - Improper Access Control
CVE-2019-12670
CWE-284 Low
No
No
16.11.1 26.09.2019 SB2019092523
#VU21351 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-12668
CWE-79 Low
No
No
- 26.09.2019 SB2019092522
#VU16928 - Memory corruption
CVE-2018-0484
CWE-119 Low
No
No
15.8.3 M1, 15.8.3.1s M, 16.6.4.12, 16.6.5 09.01.2019 SB2019011010
#VU15419 - Improper input validation
CVE-2018-0441
CWE-20 Low
No
No
- 17.10.2018 SB2018101817
#VU12071 - Cross-Site Request Forgery (CSRF)
CVE-2018-0255
CWE-352 Low
No
No
- 20.04.2018 SB2018042408
#VU8684 - Improper input validation
CVE-2017-12233
CWE-20 Low
No
Exploited
- 04.10.2017 SB2017100403
#VU8683 - Buffer overflow
CVE-2017-12240
CWE-120 High
No
Exploited
- 04.10.2017 SB2017100403
SB2017100404
#VU8682 - Improper input validation
CVE-2017-12237
CWE-20 Low
No
Exploited
- 04.10.2017 SB2017100403
SB2017100404
#VU8681 - Improper Certificate Validation
CVE-2017-12228
CWE-295 Low
No
No
- 04.10.2017 SB2017100403
SB2017100404


Showing elements 41 - 60 out of 87