VendorsCisco1100-4gltena_integrated_services_routerany version
Vulnerabilities

Cisco 1100-4gltena Integrated Services Router - any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

34CVEs
CVE-2017-12240
The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a buffer overflow condition in the DHCP relay subsystem of the affected software. An attacker could exploit this vulnerability by sending a crafted DHCP Version 4 (DHCPv4) packet to an affected system. A successful exploit could allow the attacker to execute arbitrary code and gain full control of the affected system or cause the affected system to reload, resulting in a DoS condition. Cisco Bug IDs: CSCsm45390, CSCuw77959.
Published 2017-09-28 · Analyzed
10.0KEVEPSS 0.138
CVE-2020-3387
Cisco SD-WAN vManage Software Remote Code Execution Vulnerability
Published 2020-07-16 · Modified
9.0EPSS 0.130
CVE-2020-3381
Cisco SD-WAN vManage Software Directory Traversal Vulnerability
Published 2020-07-16 · Modified
8.8EPSS 0.026
CVE-2020-3141
Cisco IOS XE Software Privilege Escalation Vulnerabilities
Published 2020-09-24 · Modified
8.8EPSS 0.018
CVE-2020-3408
Cisco IOS and IOS XE Software Split DNS Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.016
CVE-2020-3407
Cisco IOS XE Software RESTCONF and NETCONF-YANG Access Control List Denial of Service Vulnerability
Published 2020-09-24 · Modified
8.6EPSS 0.015
CVE-2023-20226
A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to the mishandling of a crafted packet stream through the AppQoE or UTD application. An attacker could exploit this vulnerability by sending a crafted packet stream through an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2023-20227
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2019-16012
Cisco SD-WAN Solution vManage SQL Injection Vulnerability
Published 2020-03-19 · Modified
8.5EPSS 0.542
CVE-2020-3180
Cisco SD-WAN Solution Software Static Credentials Vulnerability
Published 2020-07-16 · Modified
8.4EPSS 0.003
CVE-2017-12231
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the improper translation of H.323 messages that use the Registration, Admission, and Status (RAS) protocol and are sent to an affected device via IPv4 packets. An attacker could exploit this vulnerability by sending a crafted H.323 RAS packet through an affected device. A successful exploit could allow the attacker to cause the affected device to crash and reload, resulting in a DoS condition. This vulnerability affects Cisco devices that are configured to use an application layer gateway with NAT (NAT ALG) for H.323 RAS messages. By default, a NAT ALG is enabled for H.323 RAS messages. Cisco Bug IDs: CSCvc57217.
Published 2017-09-28 · Analyzed
7.8KEVEPSS 0.071
CVE-2018-0154
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.
Published 2018-03-28 · Analyzed
7.8KEVEPSS 0.071
CVE-2017-12237
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to how an affected device processes certain IKEv2 packets. An attacker could exploit this vulnerability by sending specific IKEv2 packets to an affected device to be processed. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. This vulnerability affects Cisco devices that have the Internet Security Association and Key Management Protocol (ISAKMP) enabled. Although only IKEv2 packets can be used to trigger this vulnerability, devices that are running Cisco IOS Software or Cisco IOS XE Software are vulnerable when ISAKMP is enabled. A device does not need to be configured with any IKEv2-specific features to be vulnerable. Many features use IKEv2, including different types of VPNs such as the following: LAN-to-LAN VPN; Remote-access VPN, excluding SSL VPN; Dynamic Multipoint VPN (DMVPN); and FlexVPN. Cisco Bug IDs: CSCvc41277.
Published 2017-09-28 · Analyzed
7.8KEVEPSS 0.071
CVE-2017-12234
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc43709.
Published 2017-09-28 · Analyzed
7.8KEVEPSS 0.071
CVE-2017-12233
Multiple vulnerabilities in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS 12.4 through 15.6 could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerabilities are due to the improper parsing of crafted CIP packets destined to an affected device. An attacker could exploit these vulnerabilities by sending crafted CIP packets to be processed by an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCuz95334.
Published 2017-09-28 · Analyzed
7.8KEVEPSS 0.071
CVE-2020-3266
Cisco SD-WAN Solution Command Injection Vulnerability
Published 2020-03-19 · Modified
7.8EPSS 0.006
CVE-2020-3265
Cisco SD-WAN Solution Privilege Escalation Vulnerability
Published 2020-03-19 · Modified
7.8EPSS 0.004
CVE-2020-3388
Cisco SD-WAN vManage Software Command Injection Vulnerability
Published 2020-07-16 · Modified
7.8EPSS 0.004
CVE-2020-3393
Cisco IOS XE Software IOx Application Hosting Privilege Escalation Vulnerability
Published 2020-09-24 · Modified
7.8EPSS 0.003
CVE-2020-3404
Cisco IOS XE Software Consent Token Bypass Vulnerability
Published 2020-09-24 · Modified
7.8EPSS 0.003
CVE-2020-3511
Cisco IOS and IOS XE Software ISDN Q.931 Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2020-3508
Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.004
CVE-2020-3396
Cisco IOS XE Software IOx Guest Shell USB SSD Namespace Protection Privilege Escalation Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.003
CVE-2017-12319
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.
Published 2018-03-27 · Analyzed
7.1KEVEPSS 0.052
CVE-2018-0180
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
Published 2018-03-28 · Analyzed
7.1KEVEPSS 0.049
CVE-2018-0179
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
Published 2018-03-28 · Analyzed
7.1KEVEPSS 0.049
CVE-2020-3264
Cisco SD-WAN Solution Buffer Overflow Vulnerability
Published 2020-03-19 · Modified
7.1EPSS 0.007
CVE-2021-34723
Cisco IOS XE SD-WAN Software Arbitrary File Overwrite Vulnerability
Published 2021-09-23 · Modified
6.9EPSS 0.002
CVE-2020-3401
Cisco SD-WAN vManage Software Path Traversal Vulnerability
Published 2020-07-16 · Modified
6.5EPSS 0.026
CVE-2017-12232
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.
Published 2017-09-28 · Analyzed
6.5KEVEPSS 0.022
CVE-2020-3372
Cisco SD-WAN vManage Software Denial of Service Vulnerability
Published 2020-07-16 · Modified
6.5EPSS 0.009
CVE-2020-3503
Cisco IOS XE Software Guest Shell Unauthorized File System Access Vulnerability
Published 2020-09-24 · Modified
6.0EPSS 0.003
CVE-2019-16010
Cisco SD-WAN Solution vManage Stored Cross-Site Scripting Vulnerability
Published 2020-03-19 · Modified
5.5EPSS 0.008
CVE-2020-3378
Cisco SD-WAN vManage Software SQL Injection Vulnerability
Published 2020-07-16 · Modified
4.3EPSS 0.007