Cisco vendor intelligence
Cisco Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting Cisco products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 109
- Known exploited vulnerabilities affecting Cisco products
- In CISA KEV
- 98
- Records also listed in the official catalog
- Beyond CISA KEV
- 11
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 8
- Cisco KEVs with sensor-observed exploitation activity
The catalog gap matters for Cisco exposure
Eleven of the 109 exploited Cisco vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 10% of this vendor portfolio.
- 90%
- Covered by CISA
- 10%
- Beyond CISA
- 44
- Product families
Attested Cisco vulnerabilities
109 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-12237
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12238
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12240
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated,... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-12319
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an... |
Cisco IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6627
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote... |
Cisco IOS and Cisco IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6663
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6736
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6737
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely... |
IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6738
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Cisco IOS XE Software | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6740
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6743
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6744
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0151
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0154
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0155
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0156
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0158
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0159
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0161
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0167
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and... |
Cisco IOS, IOS XE, and IOS XR | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0172
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0173
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0174
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0175
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR... |
Cisco IOS, IOS XE, and IOS XR | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0179
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0180
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2019-1652
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-20699
Cisco Small Business RV Series Routers Vulnerabilities |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-20700
Cisco Small Business RV Series Routers Vulnerabilities |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-20701
Cisco Small Business RV Series Routers Vulnerabilities |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-20703
Cisco Small Business RV Series Routers Vulnerabilities |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-20708
Cisco Small Business RV Series Routers Vulnerabilities |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2009-2055
Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid... |
IOS XR | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2010-3035
Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers... |
IOS XR | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2015-0666
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers... |
Prime Data Center Network Manager | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2017-3881
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an... |
Cisco IOS and IOS XE Software | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2018-0125
A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an... |
Cisco RV132W and RV134W | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2018-0147
A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an... |
Cisco Secure Access Control System | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2022-20821
Cisco IOS XR Software Health Check Open Port Vulnerability |
Cisco IOS XR Software | Confirmed | In CISA | 23 May 2022 |
|
CVE-2016-6367
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges... |
Adaptive Security Appliance (ASA) Software | Confirmed | In CISA | 24 May 2022 |
|
CVE-2016-6366
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv,... |
Adaptive Security Appliance (ASA) Software | Confirmed | In CISA | 24 May 2022 |
|
CVE-2019-15271
Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 08 Jun 2022 |
|
CVE-2020-3153
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability |
Cisco AnyConnect Secure Mobility Client | Confirmed | In CISA | 24 Oct 2022 |
|
CVE-2020-3433
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability |
Cisco AnyConnect Secure Mobility Client | Confirmed | In CISA | 24 Oct 2022 |
|
CVE-2017-6742
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely... |
Cisco IOS XE Software, Universal Product | Confirmed | In CISA | 19 Apr 2023 |
|
CVE-2016-6415
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x,... |
IOS, IOS XE, IOS XR, PIX | Confirmed | In CISA | 19 May 2023 |
|
CVE-2004-1464
Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP... |
IOS | Confirmed | In CISA | 19 May 2023 |
|
CVE-2023-20269
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)... |
Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software | Confirmed | In CISA | 13 Sep 2023 |
|
CVE-2023-20109
A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an... |
IOS, Cisco IOS XE Software | Confirmed | In CISA | 10 Oct 2023 |
|
CVE-2023-20198
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are... |
Cisco IOS XE Software | Confirmed | In CISA | 16 Oct 2023 |
No Cisco vulnerabilities match this search or filter.
Showing 50 of 50 on this page (109 Cisco known exploited vulnerabilities).
Recurring weakness patterns
Input validation, restriction, and resource management errors account for 42 mapped occurrences across this Cisco KEV portfolio.
CWE-20
Improper Input Validation
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-399
Resource Management Errors
CWE-121
Stack-based Buffer Overflow
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-287
Improper Authentication