Skip to main content

Vendor/product archive

cisco / ios CVEs

Beta · best-effort

602 CVEs tagged to cisco / ios32 Critical, 323 High, 236 Medium, 11 Low, 0 Unrated.

CVE-2013-5552

Published Nov 13, 2013

Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows remote attackers to bypass in…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5553

Published Nov 8, 2013

Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5548

Published Nov 1, 2013

The IKEv2 implementation in Cisco IOS, when AES-GCM or AES-GMAC is used, allows remote attackers to bypass certain IPsec anti-replay features via IPsec tunnel traffic, aka Bug ID…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5522

Published Oct 25, 2013

Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue9…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5527

Published Oct 10, 2013

The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA type 11 packet, aka Bug ID CSCui2…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5499

Published Oct 10, 2013

The remember feature in the DHCP server in Cisco IOS allows remote attackers to cause a denial of service (device reload) by acquiring a lease and then sending a DHCPRELEASE messa…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5481

Published Sep 27, 2013

The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 p…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5480

Published Sep 27, 2013

The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5479

Published Sep 27, 2013

The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5478

Published Sep 27, 2013

Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via crafted UDP R…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5477

Published Sep 27, 2013

The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denial of service (interface queue…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5476

Published Sep 27, 2013

The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attackers to cause a denial of servic…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5475

Published Sep 27, 2013

Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5474

Published Sep 27, 2013

Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers to cause a denial of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5473

Published Sep 27, 2013

Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS before 3.6.1S allows remote attackers to cause a denial of service (memory consumpti…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5472

Published Sep 27, 2013

The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSD…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5469

Published Aug 30, 2013

The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED state, which allows remote attackers to cause a denial of…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3436

Published Jul 19, 2013

The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of Interpretation (GDOI) traffic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1217

Published Apr 24, 2013

The generic input/output control implementation in Cisco IOS does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1148

Published Mar 28, 2013

The General Responder implementation in the IP Service Level Agreement (SLA) feature in Cisco IOS 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS bef…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1147

Published Mar 28, 2013

The Protocol Translation (PT) functionality in Cisco IOS 12.3 through 12.4 and 15.0 through 15.3, when one-step port-23 translation or a Telnet-to-PAD ruleset is configured, does…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-1146

Published Mar 28, 2013

The Smart Install client functionality in Cisco IOS 12.2 and 15.0 through 15.3 on Catalyst switches allows remote attackers to cause a denial of service (device reload) via crafte…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 602 CVEsPage 13 of 25