Vulnerabilities > Cisco > IOS

DATE CVE VULNERABILITY TITLE RISK
2016-05-29 CVE-2016-1409 Improper Input Validation vulnerability in Cisco products
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
network
low complexity
cisco CWE-20
7.5
2016-05-14 CVE-2016-1399 Resource Management Errors vulnerability in Cisco IOS
The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 4000 devices and 15.2(2)EB and 15.2(2)EB1 on Industrial Ethernet 5000 devices allows remote attackers to cause a denial of service (packet data corruption) via crafted IPv4 ICMP packets, aka Bug ID CSCuy13431.
network
low complexity
cisco CWE-399
7.5
2016-04-20 CVE-2016-1384 Permissions, Privileges, and Access Controls vulnerability in Cisco IOS and IOS XE
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
network
low complexity
cisco CWE-264
7.5
2016-04-14 CVE-2016-1378 Information Exposure vulnerability in Cisco IOS
Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62591.
network
low complexity
cisco CWE-200
5.3
2016-03-26 CVE-2016-1351 Resource Management Errors vulnerability in Cisco IOS and Nx-Os
The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279.
network
low complexity
cisco CWE-399
7.5
2016-03-24 CVE-2016-1347 Resource Management Errors vulnerability in Cisco IOS
The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.
network
low complexity
cisco CWE-399
7.5
2016-02-17 CVE-2016-1333 Resource Management Errors vulnerability in Cisco IOS 15.5(3)M/15.6(1)T0A
Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.
network
low complexity
cisco CWE-399
6.5
2012-03-29 CVE-2012-0384 Improper Privilege Management vulnerability in Cisco IOS
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled, allow remote authenticated users to bypass intended access restrictions and execute commands via a (1) HTTP or (2) HTTPS session, aka Bug ID CSCtr91106.
network
low complexity
cisco CWE-269
7.2
2012-03-29 CVE-2012-0382 Resource Exhaustion vulnerability in Cisco IOS
The Multicast Source Discovery Protocol (MSDP) implementation in Cisco IOS 12.0, 12.2 through 12.4, and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.1S and 3.1.xSG and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) via encapsulated IGMP data in an MSDP packet, aka Bug ID CSCtr28857.
network
low complexity
cisco CWE-400
7.5
2012-03-29 CVE-2012-0381 Cryptographic Issues vulnerability in Cisco IOS
The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2.xSG before 3.2.2SG allows remote attackers to cause a denial of service (device reload) by sending IKE UDP packets over (1) IPv4 or (2) IPv6, aka Bug ID CSCts38429.
network
low complexity
cisco CWE-310
7.5