« Back to list

Cisco

Cisco IOX: vulnerabilities and CVEs

Cisco IOX has 11 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs11
Last 12 months2
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-20113Medium (5.3)0.29%—Mar 25, 2026
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF)…
CVE-2026-20112Medium (4.8)0.19%—Mar 25, 2026
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS)…
CVE-2023-20076High (8.8)1.5%—Feb 12, 2023
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to…
CVE-2020-3238High (8.1)1.2%—Jun 3, 2020
A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual instance that is…
CVE-2020-3237Medium (6.3)0.35%—Jun 3, 2020
A vulnerability in the Cisco Application Framework component of the Cisco IOx application environment could allow an authenticated, local attacker to overwrite arbitrary files in the virtual instance that is running on…
CVE-2020-3233Medium (5.4)0.63%—Jun 3, 2020
A vulnerability in the web-based Local Manager interface of the Cisco IOx Application Framework could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the…
CVE-2017-3853Critical (9.8)8.7%—Mar 22, 2017
A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attacker to cause a stack overflow that could allow remote code execution…
CVE-2017-3852High (8.1)2.5%—Mar 22, 2017
A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an authenticated, remote attacker to write or modify arbitrary files in the virtual…
CVE-2017-3851High (7.5)5.2%—Mar 22, 2017
A Directory Traversal vulnerability in the web framework code of the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment could allow an unauthenticated, remote attacker to read…
CVE-2017-3805Medium (5.3)1.6%—Jan 26, 2017
A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated, remote attacker to view confidential information that is displayed without authenticating to the…
CVE-2016-9199Medium (6.5)2.5%—Dec 14, 2016
A vulnerability in the Cisco application-hosting framework (CAF) of Cisco IOx could allow an authenticated, remote attacker to read arbitrary files on a targeted system. Affected Products: This vulnerability affects…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1133 External Remote Services1
  3. T1204.001 Malicious Link1
  4. T1565.001 Stored Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Cisco