Cisco
Cisco IOS: vulnerabilidades y CVE
Cisco IOS tiene 624 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 8 son críticas y 39 figuran en el catálogo de explotación activa de CISA.
CVE624
Últimos 12 meses3
Críticas8
Explotadas activamente39
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2008-4128 | Alta (8.1) | 34% | ⚠ Explotación activa | 18 sept 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a… |
| CVE-2025-20352 | Alta (7.7) | 39% | ⚠ Explotación activa | 24 sept 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a… |
| CVE-2023-20109 | Media (6.6) | 2.5% | ⚠ Explotación activa | 27 sept 2023 | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has administrative control of either a group… |
| CVE-2004-1464 | Media (5.9) | 4.8% | ⚠ Explotación activa | 31 dic 2004 | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reverse Telnet port. |
| CVE-2016-6415 | Alta (7.5) | 88% | ⚠ Explotación activa | 19 sept 2016 | The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive… |
| CVE-2017-6742 | Alta (8.8) | 21% | ⚠ Explotación activa | 17 jul 2017 | The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version… |
| CVE-2017-3881 | Crítica (9.8) | 99% | ⚠ Explotación activa | 17 mar 2017 | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely… |
| CVE-2017-6743 | Alta (8.8) | 11% | ⚠ Explotación activa | 17 jul 2017 | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected… |
| CVE-2017-6663 | Media (6.5) | 2.1% | ⚠ Explotación activa | 7 ago 2017 | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting… |
| CVE-2017-6627 | Alta (7.5) | 6.2% | ⚠ Explotación activa | 7 sept 2017 | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP… |
| CVE-2017-12237 | Alta (7.5) | 7.1% | ⚠ Explotación activa | 29 sept 2017 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization,… |
| CVE-2017-12231 | Alta (7.5) | 7.1% | ⚠ Explotación activa | 29 sept 2017 | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an… |
| CVE-2017-12240 | Crítica (9.8) | 14% | ⚠ Explotación activa | 29 sept 2017 | The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an… |
| CVE-2017-12233 | Alta (7.5) | 7.1% | ⚠ Explotación activa | 29 sept 2017 | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload,… |
| CVE-2017-12235 | Alta (7.5) | 7.1% | ⚠ Explotación activa | 29 sept 2017 | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload,… |
| CVE-2017-12234 | Alta (7.5) | 7.1% | ⚠ Explotación activa | 29 sept 2017 | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload,… |
| CVE-2017-12232 | Media (6.5) | 2.2% | ⚠ Explotación activa | 29 sept 2017 | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an… |
| CVE-2017-12238 | Media (6.5) | 2.0% | ⚠ Explotación activa | 29 sept 2017 | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a C6800-16P10G or… |
| CVE-2018-0172 | Alta (8.6) | 7.8% | ⚠ Explotación activa | 28 mar 2018 | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a… |
| CVE-2018-0158 | Alta (8.6) | 7.2% | ⚠ Explotación activa | 28 mar 2018 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20301 | Alta (8.6) | 0.57% | — | 5 ago 2026 | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to… |
| CVE-2026-20125 | Alta (7.7) | 0.28% | — | 25 mar 2026 | A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a… |
| CVE-2026-20012 | Alta (8.6) | 0.35% | — | 25 mar 2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat… |
| CVE-2025-20363 | Crítica (9) | 6.9% | — | 25 sept 2025 | A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR… |
| CVE-2025-20352 | Alta (7.7) | 39% | ⚠ Explotación activa | 24 sept 2025 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a… |
| CVE-2025-20327 | Alta (7.7) | 0.39% | — | 24 sept 2025 | A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to… |
| CVE-2025-20160 | Alta (8.1) | 0.43% | — | 24 sept 2025 | A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authentication. This… |
| CVE-2025-20149 | Media (6.5) | 0.12% | — | 24 sept 2025 | A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS)… |
| CVE-2025-20253 | Alta (8.6) | 0.47% | — | 14 ago 2025 | A vulnerability in the IKEv2 feature of Cisco IOS Software, IOS XE Software, Secure Firewall ASA Software, and Secure FTD Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting… |
| CVE-2025-20239 | Alta (8.6) | 0.62% | — | 14 ago 2025 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD)… |
| CVE-2025-20225 | Media (5.8) | 0.71% | — | 14 ago 2025 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat Defense (FTD)… |
| CVE-2025-20191 | Alta (7.4) | 0.24% | — | 7 may 2025 | A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an… |
| CVE-2025-20181 | Media (6.8) | 0.19% | — | 7 may 2025 | A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated attacker with… |
| CVE-2025-20154 | Alta (8.6) | 0.51% | — | 7 may 2025 | A vulnerability in the Two-Way Active Measurement Protocol (TWAMP) server feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the affected device to reload,… |
| CVE-2025-20137 | Media (4.7) | 0.27% | — | 7 may 2025 | A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, remote attacker to… |
| CVE-2025-20176 | Alta (7.7) | 0.76% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2025-20175 | Alta (7.7) | 0.76% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2025-20174 | Alta (7.7) | 0.76% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2025-20173 | Alta (7.7) | 0.76% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2025-20172 | Alta (7.7) | 0.76% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2025-20171 | Alta (7.7) | 0.78% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2025-20170 | Alta (7.7) | 0.78% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2025-20169 | Alta (7.7) | 0.78% | — | 5 feb 2025 | A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. |
| CVE-2024-20465 | Media (5.8) | 0.42% | — | 25 sept 2024 | A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could allow an unauthenticated, remote attacker to bypass a… |
| CVE-2024-20433 | Alta (7.5) | 0.63% | — | 25 sept 2024 | A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly,… |
| CVE-2024-20414 | Media (6.5) | 0.26% | — | 25 sept 2024 | A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system through… |
| CVE-2024-20308 | Alta (7.5) | 0.80% | — | 27 mar 2024 | A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap underflow, resulting in an affected device reloading. This… |
| CVE-2024-20307 | Alta (7.5) | 0.73% | — | 27 mar 2024 | A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This… |
| CVE-2024-20312 | Alta (7.4) | 0.26% | — | 27 mar 2024 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS)… |
| CVE-2024-20311 | Alta (7.5) | 0.80% | — | 27 mar 2024 | A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
📰 Noticias relacionadas
Otros productos de Cisco
IOS XE · 581Adaptive Security Appliance Software · 354Secure Firewall Threat Defense · 299Nx-os · 286Unified Communications Manager · 241IOS XR · 213Identity Services Engine · 206Secure Firewall Management Center · 191Webex Meetings Server · 136Rv110w Firmware · 132Rv130w Firmware · 131Unified Computing System · 116