Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Cisco

Vulnerabilities in Cisco IOS XE, ASA, and other network infrastructure — the gear that, when compromised, hands attackers the keys to entire networks.

96 CVEs5 articlesRSS
CVEs
CVE-2026-20349
[ HIGH ]CVSS 8.6EPSS 0.9%kev

Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw

Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.

Cisco / Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)
CVE-2026-20316
[ MEDIUM ]CVSS 5.3EPSS 0.8%kev

Hard-coded credential in Cisco Secure FMC enables unauthenticated login

Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.

Cisco / Cisco Secure Firewall Management Center (FMC)
CVE-2026-20230
[ HIGH ]CVSS 8.6EPSS 83.2%kev

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Cisco / Unified Communications Manager
CVE-2026-20262
[ MEDIUM ]CVSS 6.5EPSS 28.2%kev

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

Cisco / Catalyst SD-WAN Manager
CVE-2026-20245
[ HIGH ]CVSS 7.8EPSS 25.3%kev

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.

Cisco / Catalyst SD-WAN Manager
CVE-2026-20182
[ CRITICAL ]CVSS 10.0EPSS 91.5%kev

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

Cisco / Catalyst SD-WAN
CVE-2026-20122
[ MEDIUM ]CVSS 5.4EPSS 24.6%kev

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

Cisco / Catalyst SD-WAN Manger
CVE-2026-20128
[ HIGH ]CVSS 7.5EPSS 6.9%kev

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.

Cisco / Catalyst SD-WAN Manager
CVE-2026-20133
[ MEDIUM ]CVSS 6.5EPSS 31.4%kev

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

Cisco / Catalyst SD-WAN Manager
CVE-2026-20131
[ CRITICAL ]CVSS 10.0EPSS 31.2%kev

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.

Cisco / Secure Firewall Management Center (FMC)
CVE-2022-20775
[ HIGH ]CVSS 7.8EPSS 12.5%kev

Cisco SD-WAN Path Traversal Vulnerability

Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.

Cisco / SD-WAN
CVE-2026-20127
[ CRITICAL ]CVSS 10.0EPSS 88.2%kev

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.

Cisco / Catalyst SD-WAN Controller and Manager
CVE-2026-20045
[ HIGH ]CVSS 8.2EPSS 4.3%kev

Cisco Unified Communications Products Code Injection Vulnerability

Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.

Cisco / Unified Communications Manager
CVE-2025-20393
[ CRITICAL ]CVSS 10.0EPSS 29.9%kev

Cisco Multiple Products Improper Input Validation Vulnerability

Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.

Cisco / Multiple Products
CVE-2025-20352
[ HIGH ]CVSS 7.7EPSS 38.8%kev

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.

Cisco / IOS and IOS XE
CVE-2025-20333
[ CRITICAL ]CVSS 9.9EPSS 40.4%kev

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.

Cisco / Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CVE-2025-20362
[ MEDIUM ]CVSS 6.5EPSS 86.9%kev

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.

Cisco / Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CVE-2025-20281
[ CRITICAL ]CVSS 10.0EPSS 97.1%kev

Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Cisco / Identity Services Engine
CVE-2025-20337
[ CRITICAL ]CVSS 10.0EPSS 66.3%kev

Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.

Cisco / Identity Services Engine
CVE-2024-20439
[ CRITICAL ]CVSS 9.8EPSS 92.1%kev

Cisco Smart Licensing Utility Static Credential Vulnerability

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

Cisco / Smart Licensing Utility
CVE-2023-20118
[ MEDIUM ]CVSS 6.5EPSS 54.1%kev

Cisco Small Business RV Series Routers Command Injection Vulnerability

Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.

Cisco / Small Business RV Series Routers
CVE-2014-2120
[ MEDIUM ]CVSS 6.1EPSS 18.9%kev

Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

Cisco / Adaptive Security Appliance (ASA)
CVE-2024-20481
[ MEDIUM ]CVSS 5.8EPSS 15.9%kev

Cisco ASA and FTD Denial-of-Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.

Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2024-20399
[ MEDIUM ]CVSS 6.0EPSS 4.3%kev

Cisco NX-OS Command Injection Vulnerability

Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.

Cisco / NX-OS
CVE-2024-20353
[ HIGH ]CVSS 8.6EPSS 70.7%kev

Cisco ASA and FTD Denial of Service Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.

Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2024-20359
[ MEDIUM ]CVSS 6.0EPSS 19.4%kev

Cisco ASA and FTD Privilege Escalation Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.

Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2020-3259
[ HIGH ]CVSS 7.5EPSS 69.3%kev

Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.

Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2023-20273
[ HIGH ]CVSS 7.2EPSS 89.6%kev

Cisco IOS XE Web UI Command Injection Vulnerability

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

Cisco / Cisco IOS XE Web UI
CVE-2023-20198
[ CRITICAL ]CVSS 10.0EPSS 99.6%kev

Cisco IOS XE Web UI Privilege Escalation Zero-Day

A privilege-escalation vulnerability in the Web UI feature of Cisco IOS XE Software allows a remote, unauthenticated attacker to create an account with privilege level 15 (full admin) access, enabling full device takeover. Exploited at mass scale against tens of thousands of devices.

Cisco / IOS XE Software
CVE-2023-20109
[ MEDIUM ]CVSS 6.6EPSS 2.3%kev

Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.

Cisco / IOS and IOS XE
CVE-2023-20269
[ MEDIUM ]CVSS 5.0EPSS 21.6%kev

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.

Cisco / Adaptive Security Appliance and Firepower Threat Defense
CVE-2004-1464
[ MEDIUM ]CVSS 5.9EPSS 4.7%kev

Cisco IOS Denial-of-Service Vulnerability

Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.

Cisco / IOS
CVE-2016-6415
[ HIGH ]CVSS 7.5EPSS 87.3%kev

Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.

Cisco / IOS, IOS XR, and IOS XE
CVE-2017-6742
[ HIGH ]CVSS 8.8EPSS 21.4%kev

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Cisco / IOS and IOS XE Software
CVE-2020-3153
[ MEDIUM ]CVSS 6.5EPSS 27.5%kev

Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.

Cisco / AnyConnect Secure
CVE-2020-3433
[ HIGH ]CVSS 7.8EPSS 10.0%kev

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.

Cisco / AnyConnect Secure
CVE-2019-15271
[ HIGH ]CVSS 8.8EPSS 6.0%kev

Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.

Cisco / RV Series Routers
CVE-2016-6366
[ HIGH ]CVSS 8.8EPSS 87.6%kev

Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.

Cisco / Adaptive Security Appliance (ASA)
CVE-2016-6367
[ HIGH ]CVSS 7.8EPSS 22.6%kev

Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

Cisco / Adaptive Security Appliance (ASA)
CVE-2022-20821
[ MEDIUM ]CVSS 6.5EPSS 12.1%kev

Cisco IOS XR Open Port Vulnerability

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

Cisco / IOS XR
CVE-2009-2055
[ MEDIUM ]CVSS 5.9EPSS 3.3%kev

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

Cisco / IOS XR
CVE-2010-3035
[ HIGH ]CVSS 7.5EPSS 5.6%kev

Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).

Cisco / IOS XR
CVE-2015-0666
[ HIGH ]CVSS 7.5EPSS 40.4%kev

Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.

Cisco / Prime Data Center Network Manager (DCNM)
CVE-2017-3881
[ CRITICAL ]CVSS 9.8EPSS 99.0%kev

Cisco IOS and IOS XE Remote Code Execution Vulnerability

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.

Cisco / IOS and IOS XE
CVE-2018-0125
[ CRITICAL ]CVSS 9.8EPSS 55.2%kev

Cisco VPN Routers Remote Code Execution Vulnerability

A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.

Cisco / VPN Routers
CVE-2018-0147
[ CRITICAL ]CVSS 9.8EPSS 18.3%kev

Cisco Secure Access Control System Java Deserialization Vulnerability

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.

Cisco / Secure Access Control System (ACS)
CVE-2017-12231
[ HIGH ]CVSS 7.5EPSS 7.1%kev

Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.

Cisco / IOS software
CVE-2017-12232
[ MEDIUM ]CVSS 6.5EPSS 2.2%kev

Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.

Cisco / IOS software
CVE-2017-12233
[ HIGH ]CVSS 7.5EPSS 7.1%kev

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

Cisco / IOS software
CVE-2017-12234
[ HIGH ]CVSS 7.5EPSS 7.1%kev

Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

Cisco / IOS software
CVE-2017-12235
[ HIGH ]CVSS 7.5EPSS 7.1%kev

Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.

Cisco / IOS software
CVE-2017-12237
[ HIGH ]CVSS 7.5EPSS 7.1%kev

Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.

Cisco / IOS and IOS XE Software
CVE-2017-12238
[ MEDIUM ]CVSS 6.5EPSS 2.0%kev

Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.

Cisco / Catalyst 6800 Series Switches
CVE-2017-12240
[ CRITICAL ]CVSS 9.8EPSS 13.9%kev

Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.

Cisco / IOS and IOS XE Software
CVE-2017-12319
[ MEDIUM ]CVSS 5.9EPSS 5.3%kev

Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.

Cisco / IOS XE Software
CVE-2017-6627
[ HIGH ]CVSS 7.5EPSS 6.0%kev

Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.

Cisco / IOS and IOS XE Software
CVE-2017-6663
[ MEDIUM ]CVSS 6.5EPSS 2.1%kev

Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).

Cisco / IOS and IOS XE Software
CVE-2017-6736
[ HIGH ]CVSS 8.8EPSS 70.6%kev

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Cisco / IOS and IOS XE Software
CVE-2017-6737
[ HIGH ]CVSS 8.8EPSS 42.6%kev

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Cisco / IOS and IOS XE Software
CVE-2017-6738
[ HIGH ]CVSS 8.8EPSS 10.5%kev

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Cisco / IOS and IOS XE Software
CVE-2017-6739
[ HIGH ]CVSS 8.8EPSS 10.5%kev

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Cisco / IOS and IOS XE Software
CVE-2017-6740
[ HIGH ]CVSS 8.8EPSS 10.8%kev

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Cisco / IOS and IOS XE Software
CVE-2017-6743
[ HIGH ]CVSS 8.8EPSS 10.5%kev

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.

Cisco / IOS and IOS XE Software
CVE-2017-6744
[ HIGH ]CVSS 8.8EPSS 7.2%kev

Cisco IOS Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6.

Cisco / IOS software
CVE-2018-0151
[ CRITICAL ]CVSS 9.8EPSS 14.3%kev

Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.

Cisco / IOS and IOS XE Software
CVE-2018-0154
[ HIGH ]CVSS 7.5EPSS 7.1%kev

Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.

Cisco / IOS Software
CVE-2018-0155
[ HIGH ]CVSS 8.6EPSS 7.8%kev

Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.

Cisco / Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches
CVE-2018-0156
[ HIGH ]CVSS 7.5EPSS 8.2%kev

Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.

Cisco / IOS Software and Cisco IOS XE Software
CVE-2018-0158
[ HIGH ]CVSS 8.6EPSS 7.2%kev

Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

Cisco / IOS Software and Cisco IOS XE Software
CVE-2018-0159
[ HIGH ]CVSS 7.5EPSS 6.9%kev

Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.

Cisco / IOS Software and Cisco IOS XE Software
CVE-2018-0161
[ MEDIUM ]CVSS 6.3EPSS 4.7%kev

Cisco IOS Software Resource Management Errors Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.

Cisco / IOS Software
CVE-2018-0167
[ HIGH ]CVSS 8.8EPSS 3.4%kev

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.

Cisco / IOS, XR, and XE Software
CVE-2018-0172
[ HIGH ]CVSS 8.6EPSS 7.9%kev

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

Cisco / IOS and IOS XE Software
CVE-2018-0173
[ HIGH ]CVSS 8.6EPSS 7.7%kev

Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).

Cisco / IOS and IOS XE Software
CVE-2018-0174
[ HIGH ]CVSS 8.6EPSS 7.7%kev

Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).

Cisco / IOS XE Software
CVE-2018-0175
[ HIGH ]CVSS 8.0EPSS 3.5%kev

Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.

Cisco / IOS, XR, and XE Software
CVE-2018-0179
[ MEDIUM ]CVSS 5.9EPSS 5.0%kev

Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

Cisco / IOS Software
CVE-2018-0180
[ MEDIUM ]CVSS 5.9EPSS 5.0%kev

Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.

Cisco / IOS Software
CVE-2019-1652
[ HIGH ]CVSS 7.2EPSS 95.9%kev

Cisco Small Business Routers Improper Input Validation Vulnerability

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.

Cisco / Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers
CVE-2022-20699
[ CRITICAL ]CVSS 10.0EPSS 72.5%kev

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers
CVE-2022-20700
[ CRITICAL ]CVSS 10.0EPSS 5.7%kev

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers
CVE-2022-20701
[ CRITICAL ]CVSS 10.0EPSS 9.7%kev

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers
CVE-2022-20703
[ CRITICAL ]CVSS 10.0EPSS 9.2%kev

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers
CVE-2022-20708
[ CRITICAL ]CVSS 10.0EPSS 14.9%kev

Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).

Cisco / Small Business RV160, RV260, RV340, and RV345 Series Routers
CVE-2018-0296
[ HIGH ]CVSS 7.5EPSS 99.9%kev

Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.

Cisco / Adaptive Security Appliance (ASA)
CVE-2019-1653
[ HIGH ]CVSS 7.5EPSS 99.9%kev

Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.

Cisco / Small Business RV320 and RV325 Routers
CVE-2020-3118
[ HIGH ]CVSS 8.8EPSS 11.7%kev

Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.

Cisco / IOS XR
CVE-2020-3161
[ CRITICAL ]CVSS 9.8EPSS 83.7%kev

Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

Cisco / Cisco IP Phones
CVE-2020-3452
[ HIGH ]CVSS 7.5EPSS 100.0%kev

Cisco ASA and FTD Read-Only Path Traversal Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.

Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2020-3566
[ HIGH ]CVSS 8.6EPSS 3.7%kev

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

Cisco / IOS XR
CVE-2020-3569
[ HIGH ]CVSS 8.6EPSS 3.3%kev

Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.

Cisco / IOS XR
CVE-2020-3580
[ MEDIUM ]CVSS 6.1EPSS 85.6%kev

Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.

Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
CVE-2021-1497
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

Cisco / HyperFlex HX
CVE-2021-1498
[ CRITICAL ]CVSS 9.8EPSS 100.0%kev

Cisco HyperFlex HX Data Platform Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

Cisco / HyperFlex HX
CVE-2018-0171
[ CRITICAL ]CVSS 9.8EPSS 99.5%kev

Cisco Smart Install unauthenticated RCE in IOS and IOS XE

Unauthenticated remote code execution in the Cisco Smart Install client on IOS and IOS XE. Patched by Cisco in March 2018 and still the primary access vector FSB Centre 16 uses against edge routers on critical-infrastructure networks per a July 2026 joint advisory.

Cisco / IOS and IOS XE with Smart Install client enabled
CVE-2008-4128
[ MEDIUM ]CVSS 4.3EPSS 33.0%kev

Cisco IOS 12.4 HTTP admin CSRF on the 871 Integrated Services Router

Multiple CSRF flaws in the HTTP admin component of Cisco IOS 12.4 (on the 871 ISR) allow remote command execution via crafted /level/15/exec/ requests. Added to CISA KEV 2026-07-13.

Cisco / IOS 12.4 mainline (Cisco 871 Integrated Services Router)
Articles
~/articles/2026-08-11-cisco-asa-ftd-cve-2026-20349-kev-dos-vpn
Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline
cisco

Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline

CVE-2026-20349 added to CISA KEV today. Unauthenticated attackers can crash Cisco ASA and FTD devices over VPN — CISA's due date is August 14.

read →
~/articles/2026-07-29-cisco-fmc-cve-2026-20316-kev-hardcoded-credential
CISA KEV: Cisco FMC Hard-Coded Password Now Exploited
cisco

CISA KEV: Cisco FMC Hard-Coded Password Now Exploited

CISA added CVE-2026-20316 to its KEV catalog. Cisco Secure FMC carries a hardcoded credential—medium CVSS, High by Cisco's own rating, now confirmed exploited.

read →
~/articles/2026-07-13-cisa-kev-cve-2008-4128-cisco-ios-12-4-csrf
Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV
cisco

Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV

CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.

read →
~/articles/2026-07-03-cisco-unified-cm-active-exploitation-confirmed
Cisco Confirms Active Exploitation of Unified CM Flaw
cisco

Cisco Confirms Active Exploitation of Unified CM Flaw

Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

read →
~/articles/2026-06-24-cisco-ios-xe-web-ui-zero-day-mass-exploitation
Cisco IOS XE Web UI Zero-Day: Mass Exploitation
Explainer
cisco

Cisco IOS XE Web UI Zero-Day: Mass Exploitation

CVE-2023-20198, a maximum-severity privilege-escalation flaw in Cisco IOS XE's web management interface, was exploited at mass scale before a patch existed — handing attackers full admin control of network infrastructure.

read →