Skip to main content

Vendor/product archive

cisco / ios CVEs

Beta · best-effort

602 CVEs tagged to cisco / ios32 Critical, 323 High, 236 Medium, 11 Low, 0 Unrated.

CVE-2012-5032

Published Apr 23, 2014

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5036

Published Apr 23, 2014

Cisco IOS before 12.2(50)SY1 allows remote authenticated users to cause a denial of service (memory consumption) via a sequence of VTY management sessions (aka exec sessions), aka…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4658

Published Apr 23, 2014

The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger inc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5014

Published Apr 23, 2014

Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4651

Published Apr 23, 2014

Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets fro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4638

Published Apr 23, 2014

Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establishing an outbound SSH session, aka Bug ID CSCto00318.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3062

Published Apr 23, 2014

Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1317

Published Apr 23, 2014

The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0360

Published Apr 23, 2014

Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2143

Published Apr 4, 2014

The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2131

Published Mar 29, 2014

The packet driver in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a series of (1) Virtual Switching Systems (VSS) or (2) Bidirectional Forwar…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2113

Published Mar 27, 2014

Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2112

Published Mar 27, 2014

The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSC…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2111

Published Mar 27, 2014

The Application Layer Gateway (ALG) module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (device rel…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2109

Published Mar 27, 2014

The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device rel…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2108

Published Mar 27, 2014

Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a denial of service (device reloa…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2107

Published Mar 27, 2014

Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attackers to cause a denial of servi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2106

Published Mar 27, 2014

Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2124

Published Mar 21, 2014

Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of service (device crash) via…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6705

Published Dec 3, 2013

The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device reload) via a crafted sequence o…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6694

Published Nov 22, 2013

The IPSec implementation in Cisco IOS allows remote attackers to cause a denial of service (MTU change and tunnel-session drop) via crafted ICMP packets, aka Bug ID CSCul29918.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6693

Published Nov 22, 2013

The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption an…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6686

Published Nov 18, 2013

The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 602 CVEsPage 12 of 25