Cisco Ios
Vendor:
First CVE: Mar 27, 2008 · Active for 18 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Cisco Ios over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2008
18 years ago
Most Recent CVE
Jun 23, 2015
4,050 days ago
CVE Severity & Scoring
Cisco Ios8 CVEs
25%
75%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0960HIGH SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC | Jun 10, 2008 | 10.0 | 77 | NO | YES |
CVE-2008-1152HIGH The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) | Mar 27, 2008 | 7.8 | 24 | NO | NO |
CVE-2009-0628HIGH Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL | Mar 27, 2009 | 9.0 | 23 | NO | NO |
CVE-2008-1153HIGH Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked | Mar 27, 2008 | 7.1 | 22 | NO | NO |
CVE-2015-4204MEDIUM Memory leak in Cisco IOS 12.2 in the Performance Routing Engine (PRE) module on uBR10000 devices allows remote authenticated users to cause a denial of service (memory consumption | Jun 23, 2015 | 6.8 | 19 | NO | NO |
CVE-2009-0634HIGH Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 a | Mar 27, 2009 | 7.1 | 19 | NO | NO |
CVE-2009-0633HIGH Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denia | Mar 27, 2009 | 7.1 | 19 | NO | NO |
CVE-2008-1156MEDIUM Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast | Mar 27, 2008 | 5.1 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Cisco Ios
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 12.4 | 6 | 7.7 | 2.9% | 0 | 0 |
| 12.3 | 6 | 7.7 | 2.8% | 0 | 0 |
| 12.2\(33\) | 1 | 6.8 | 2.7% | 0 | 0 |
| 12.2 | 2 | 7.8 | 3.7% | 0 | 0 |
| 12.1 | 1 | 7.8 | 3.7% | 0 | 0 |
| 12.0 | 1 | 7.8 | 3.7% | 0 | 0 |