📦 Ios

by Cisco

🔍 What is Ios?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20363

CRITICAL CVSS 9.0 Sep 25, 2025

This critical vulnerability allows remote attackers to execute arbitrary code with root privileges on affected Cisco devices. Unauthenticated attackers can exploit Cisco ASA/FTD devices, while authent...

CVE-2025-20154

HIGH CVSS 8.6 May 7, 2025

An out-of-bounds array access vulnerability in Cisco's TWAMP server implementation allows unauthenticated remote attackers to cause device reloads (DoS) by sending crafted TWAMP control packets. Affec...

CVE-2025-20172

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS, IOS XE, and IOS XR Software allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. This affects devices with SNMP enabled usin...

CVE-2025-20173

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects devices running vul...

CVE-2025-20174

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects devices running vul...

CVE-2025-20175

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects SNMP versions 1, 2c...

CVE-2025-20176

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. This affects devices running vulnerable softw...

CVE-2025-20170

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. This affects devices running vulnerable Cisco...

CVE-2025-20171

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects SNMP versions 1, 2c...

CVE-2025-20169

HIGH CVSS 7.7 Feb 5, 2025

A vulnerability in Cisco IOS and IOS XE SNMP subsystems allows authenticated remote attackers to cause denial of service by sending crafted SNMP requests. The vulnerability affects devices running vul...

CVE-2024-20433

HIGH CVSS 8.6 Sep 25, 2024

An unauthenticated remote attacker can send specially crafted RSVP packets to vulnerable Cisco devices, causing a buffer overflow that forces the device to reboot. This results in a denial of service ...

CVE-2024-20308

HIGH CVSS 8.6 Mar 27, 2024

A heap underflow vulnerability in Cisco IOS/IOS XE IKEv1 fragmentation handling allows unauthenticated remote attackers to trigger device reloads via crafted UDP packets. This affects systems running ...

CVE-2024-20311

HIGH CVSS 8.6 Mar 27, 2024

An unauthenticated remote attacker can send specially crafted LISP packets to vulnerable Cisco devices, causing them to reload and creating a denial of service condition. This affects Cisco IOS and IO...

CVE-2023-20186

HIGH CVSS 8.0 Sep 27, 2023

This vulnerability allows authenticated remote attackers with level 15 privileges to bypass AAA command authorization checks when using SCP, enabling them to copy files to/from affected Cisco devices....

CVE-2023-20080

HIGH CVSS 8.6 Mar 23, 2023

An unauthenticated remote attacker can send crafted DHCPv6 messages to Cisco IOS/IOS XE devices with DHCPv6 relay or server features enabled, causing the device to reload unexpectedly due to insuffici...

CVE-2022-20761

HIGH CVSS 7.4 Apr 15, 2022

An unauthenticated attacker on the same network can send crafted traffic to Cisco CGR1K routers, causing the integrated wireless access point to stop processing traffic. This denial-of-service conditi...

CVE-2021-34714

HIGH CVSS 7.4 Sep 23, 2021

This vulnerability allows an unauthenticated attacker on the same network segment to send specially crafted UDLD packets to Cisco networking devices, causing them to reload and creating a denial of se...

CVE-2021-34699

HIGH CVSS 7.7 Sep 23, 2021

This vulnerability in Cisco IOS and IOS XE software allows authenticated remote attackers to trigger a device reload via a specific CLI command through the web UI, causing a denial of service (DoS). I...

CVE-2021-1392

HIGH CVSS 7.8 Mar 24, 2021

This vulnerability allows authenticated local attackers on Cisco IOS/IOS XE devices to retrieve Common Industrial Protocol (CIP) passwords via a misconfigured CLI command. Attackers can then use these...

CVE-2025-20181

MEDIUM CVSS 6.8 May 7, 2025

This vulnerability allows authenticated local attackers with privilege level 15 or unauthenticated attackers with physical access to execute persistent code during device boot by bypassing signature v...

CVE-2024-20465

MEDIUM CVSS 5.8 Sep 25, 2024

This vulnerability allows unauthenticated remote attackers to bypass configured IPv4 access control lists on affected Cisco switches when Resilient Ethernet Protocol is toggled. It affects Cisco Indus...