Ios

Vendor:

First CVE: Dec 10, 1992 · Active for 33 years

616
Total CVEs
More Total CVEs than 100% of tracked products
19.9
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
6.3%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ios over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 1992
33 years ago
Most Recent CVE
Sep 25, 2025
302 days ago

CVE Severity & Scoring

Ios616 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local23 (3.7%)
Network163 (26.5%)
Unknown397 (64.4%)
Physical3 (0.5%)
Adjacent Network30 (4.9%)
Attack Complexity
Low195 (31.7%)
High24 (3.9%)
Unknown397 (64.4%)
User Interaction
None205 (33.3%)
Unknown397 (64.4%)
Required14 (2.3%)
Privileges Required
Low44 (7.1%)
High22 (3.6%)
None153 (24.8%)
Unknown397 (64.4%)

Top CVEs

Signals from CVEs in this product scope (616 CVEs).

616 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a rel
Mar 17, 20179.899YESYES
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected devi
Mar 28, 20189.898YESYES
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote a
Sep 19, 20167.597YESYES
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to rem
Jul 17, 20178.894YESYES
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; an
Jul 8, 20086.887NOYES
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access
Jul 21, 20019.386NOYES
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote
Sep 24, 20257.785YESNO
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary
Dec 23, 200210.085NOYES
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could
Jul 17, 20178.884YESNO
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to ex
Sep 18, 20084.379YESYES

Exploit Exposure

Signals from CVEs in this product scope (616 CVEs).

CISA KEV
39 CVEs
6.3% of CVEs· 97th percentile
Metasploit
7 CVEs
1.1% of CVEs· 96th percentile
Nuclei
3 CVEs
0.5% of CVEs· 96th percentile
ExploitDB
31 CVEs
5.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (616 CVEs).

Media Mentions

Signals from CVEs in this product scope (616 CVEs).

Top CNAs Publishing CVEs For Ios

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
fd-1.5.017.41.1%00
everest-16.5.118.61.6%00
denali-16.3.618.61.6%00
denali-16.3.418.67.8%10
9.1445.39.2%00
9.166.26.8%00
9.046.69.7%00
8.346.69.7%00
8.246.69.7%00
7.2\(2\)2225.55.5%01
700015.095.7%01
5.2.0.base18.83.4%10
4.1.246.09.4%00
4.1.146.09.4%00
4.156.37.7%00
3.6\(2\)e18.67.9%10
3.16.115.31.7%00
2.315.91.1%00
1.8.017.51.8%00
17.8.115.90.7%00