Cisco vendor intelligence

Cisco Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Cisco products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse KEVs Full KEV feed
Total KEVs
109
Known exploited vulnerabilities affecting Cisco products
In CISA KEV
98
Records also listed in the official catalog
Beyond CISA KEV
11
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
8
Cisco KEVs with sensor-observed exploitation activity

The catalog gap matters for Cisco exposure

Eleven of the 109 exploited Cisco vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 10% of this vendor portfolio.

90%
Covered by CISA
10%
Beyond CISA
44
Product families

Attested Cisco vulnerabilities

109 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2017-12237

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-12238

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2017-12240

The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated,...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-12319

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an...

Cisco IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-6627

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote...

Cisco IOS and Cisco IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-6663

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2017-6736

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2017-6737

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...

IOS Confirmed In CISA 03 Mar 2022
CVE-2017-6738

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Cisco IOS XE Software Confirmed In CISA 03 Mar 2022
CVE-2017-6740

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2017-6743

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2017-6744

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

IOS, Universal Product Confirmed In CISA 03 Mar 2022
CVE-2018-0151

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0154

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2018-0155

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0156

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0158

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0159

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0161

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2018-0167

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and...

Cisco IOS, IOS XE, and IOS XR Confirmed In CISA 03 Mar 2022
CVE-2018-0172

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0173

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0174

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...

Cisco IOS and IOS XE Confirmed In CISA 03 Mar 2022
CVE-2018-0175

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR...

Cisco IOS, IOS XE, and IOS XR Confirmed In CISA 03 Mar 2022
CVE-2018-0179

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2018-0180

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...

Cisco IOS Confirmed In CISA 03 Mar 2022
CVE-2019-1652

Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20699

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20700

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20701

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20703

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2022-20708

Cisco Small Business RV Series Routers Vulnerabilities

Cisco Small Business RV Series Router Firmware Confirmed In CISA 03 Mar 2022
CVE-2009-2055

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid...

IOS XR Confirmed In CISA 25 Mar 2022
CVE-2010-3035

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers...

IOS XR Confirmed In CISA 25 Mar 2022
CVE-2015-0666

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers...

Prime Data Center Network Manager Confirmed In CISA 25 Mar 2022
CVE-2017-3881

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an...

Cisco IOS and IOS XE Software Confirmed In CISA 25 Mar 2022
CVE-2018-0125

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an...

Cisco RV132W and RV134W Confirmed In CISA 25 Mar 2022
CVE-2018-0147

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an...

Cisco Secure Access Control System Confirmed In CISA 25 Mar 2022
CVE-2022-20821

Cisco IOS XR Software Health Check Open Port Vulnerability

Cisco IOS XR Software Confirmed In CISA 23 May 2022
CVE-2016-6367

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges...

Adaptive Security Appliance (ASA) Software Confirmed In CISA 24 May 2022
CVE-2016-6366

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv,...

Adaptive Security Appliance (ASA) Software Confirmed In CISA 24 May 2022
CVE-2019-15271

Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability

Cisco Small Business RV Series Router Firmware Confirmed In CISA 08 Jun 2022
CVE-2020-3153

Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Cisco AnyConnect Secure Mobility Client Confirmed In CISA 24 Oct 2022
CVE-2020-3433

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Cisco AnyConnect Secure Mobility Client Confirmed In CISA 24 Oct 2022
CVE-2017-6742

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...

Cisco IOS XE Software, Universal Product Confirmed In CISA 19 Apr 2023
CVE-2016-6415

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x,...

IOS, IOS XE, IOS XR, PIX Confirmed In CISA 19 May 2023
CVE-2004-1464

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP...

IOS Confirmed In CISA 19 May 2023
CVE-2023-20269

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...

Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense Software Confirmed In CISA 13 Sep 2023
CVE-2023-20109

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an...

IOS, Cisco IOS XE Software Confirmed In CISA 10 Oct 2023
CVE-2023-20198

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are...

Cisco IOS XE Software Confirmed In CISA 16 Oct 2023

Showing 50 of 50 on this page (109 Cisco known exploited vulnerabilities).

Recurring weakness patterns

Input validation, restriction, and resource management errors account for 42 mapped occurrences across this Cisco KEV portfolio.

Browse all KEVs →