Cisco IOS / IOS XE
Our sources currently list 961 known vulnerabilities affecting Cisco IOS / IOS XE. 44 are rated critical severity. 43 of 961 are actively exploited according to CISA, the most recent added 13 July 2026.
Last updated: 22 July 2026, 20:20 AEST
Australian advisories
| CVE | Severity | Exploitation | Published | Summary |
|---|---|---|---|---|
| CVE-2023-44487 | High (7.5) | Actively exploited | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through… | |
| CVE-2023-20198 | Critical (10.0) | Actively exploited | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and… | |
| CVE-2018-0171 | Critical (9.8) | Actively exploited | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected devi… | |
| CVE-2017-3881 | Critical (9.8) | Actively exploited | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a rel… | |
| CVE-2023-20273 | High (7.2) | Actively exploited | A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges of root. This vulnerability is d… | |
| CVE-2016-6415 | High (7.5) | Actively exploited | The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote a… | |
| CVE-2017-6736 | High (8.8) | Actively exploited | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to rem… | |
| CVE-2017-6737 | High (8.8) | Actively exploited | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could … | |
| CVE-2025-20352 | High (7.7) | Actively exploited | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote … | |
| CVE-2008-4128 | Medium (4.3) | Actively exploited | Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to ex… | |
| CVE-2017-6742 | High (8.8) | Actively exploited | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could … | |
| CVE-2018-0151 | Critical (9.8) | Actively exploited | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of servi… | |
| CVE-2017-12240 | Critical (9.8) | Actively exploited | The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary… | |
| CVE-2017-6740 | High (8.8) | Actively exploited | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to rem… | |
| CVE-2017-6738 | High (8.8) | Actively exploited | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to rem… | |
| CVE-2017-6739 | High (8.8) | Actively exploited | A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could … | |
| CVE-2017-6743 | High (8.8) | Actively exploited | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to rem… | |
| CVE-2018-0156 | High (7.5) | Actively exploited | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected devi… | |
| CVE-2018-0172 | High (8.6) | Actively exploited | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affect… | |
| CVE-2018-0155 | High (8.6) | Actively exploited | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow … | |
| CVE-2018-0173 | High (8.6) | Actively exploited | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unau… | |
| CVE-2018-0174 | High (8.6) | Actively exploited | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affect… | |
| CVE-2018-0158 | High (8.6) | Actively exploited | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a mem… | |
| CVE-2018-0154 | High (7.5) | Actively exploited | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a… | |
| CVE-2017-6744 | High (8.8) | Actively exploited | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to rem… | |
| CVE-2017-12231 | High (7.5) | Actively exploited | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a d… | |
| CVE-2017-12233 | High (7.5) | Actively exploited | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cau… | |
| CVE-2017-12234 | High (7.5) | Actively exploited | Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cau… | |
| CVE-2017-12235 | High (7.5) | Actively exploited | A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS 12.2 through 15.6 could allow an unauthenticated, remote attacker … | |
| CVE-2017-12237 | High (7.5) | Actively exploited | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attack… | |
| CVE-2018-0159 | High (7.5) | Actively exploited | A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remot… | |
| CVE-2017-6627 | High (7.5) | Actively exploited | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue o… | |
| CVE-2017-12319 | Medium (5.9) | Actively exploited | A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to ca… | |
| CVE-2004-1464 | Medium (5.9) | Actively exploited | Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP connection to the Telnet or reve… | |
| CVE-2018-0179 | Medium (5.9) | Actively exploited | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected sy… | |
| CVE-2018-0180 | Medium (5.9) | Actively exploited | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected sy… | |
| CVE-2018-0161 | Medium (6.3) | Actively exploited | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, … | |
| CVE-2018-0175 | High (8.0) | Actively exploited | Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthentic… | |
| CVE-2018-0167 | High (8.8) | Actively exploited | Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow a… | |
| CVE-2023-20109 | Medium (6.6) | Actively exploited | A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker who has a… | |
| CVE-2017-12232 | Medium (6.5) | Actively exploited | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenti… | |
| CVE-2017-6663 | Medium (6.5) | Actively exploited | A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an… | |
| CVE-2017-12238 | Medium (6.5) | Actively exploited | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attac… | |
| CVE-1999-0016 | Medium (5.0) | Elevated likelihood (96%) | Land IP denial of service. | |
| CVE-2008-1447 | Medium (6.8) | Elevated likelihood (95%) | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; an… | |
| CVE-2002-1359 | Critical (10.0) | Elevated likelihood (80%) | Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary … | |
| CVE-2008-0960 | Critical (10.0) | Elevated likelihood (69%) | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC… | |
| CVE-2001-0537 | Critical (9.3) | Elevated likelihood (68%) | HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access… | |
| CVE-2021-1384 | Medium (6.5) | Elevated likelihood (35%) | A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating… | |
| CVE-2000-0380 | High (7.1) | Elevated likelihood (35%) | The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string. |
Vulnerability data from the NVD andCISA KEV(US Government, public domain); Australian advisories fromASD’s ACSC (CC BY 4.0). Exploit-probability scores from FIRST EPSS.
Let's talk
43 of these are being actively exploited right now.
Our Newcastle team can audit your Cisco estate, tell you in plain English which of these actually affect you, and patch them — fixed quote, no obligation.
