VendorsCiscocloud_services_router_1000vany version
Vulnerabilities

Cisco Cloud Services Router any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2019-12643
Cisco REST API Container for IOS XE Software Authentication Bypass Vulnerability
Published 2019-08-28 · Modified
10.0EPSS 0.053
CVE-2019-12650
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Published 2019-09-25 · Modified
9.0EPSS 0.289
CVE-2019-12651
Cisco IOS XE Software Web UI Command Injection Vulnerabilities
Published 2019-09-25 · Modified
9.0EPSS 0.025
CVE-2020-3425
Cisco IOS XE Software Privilege Escalation Vulnerabilities
Published 2020-09-24 · Modified
8.8EPSS 0.018
CVE-2019-1904
Cisco IOS XE Software Web UI Cross-Site Request Forgery Vulnerability
Published 2019-06-21 · Modified
8.8EPSS 0.010
CVE-2018-0173
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a Relay Reply denial of service (DoS) condition. The vulnerability exists because the affected software performs incomplete input validation of encapsulated option 82 information that it receives in DHCPOFFER messages from DHCPv4 servers. An attacker could exploit this vulnerability by sending a crafted DHCPv4 packet to an affected device, which the device would then forward to a DHCPv4 server. When the affected software processes the option 82 information that is encapsulated in the response from the server, an error could occur. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvg62754.
Published 2018-03-28 · Analyzed
8.6KEVEPSS 0.076
CVE-2019-12647
Cisco IOS and IOS XE Software IP Ident Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12654
Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2019-12657
Cisco IOS XE Software Unified Threat Defense Denial of Service Vulnerability
Published 2019-09-25 · Modified
8.6EPSS 0.020
CVE-2020-3480
Cisco IOS XE Software Zone-Based Firewall Denial of Service Vulnerabilities
Published 2020-09-24 · Modified
8.6EPSS 0.014
CVE-2023-20027
Cisco IOS XE Software Virtual Fragmentation Reassembly Denial of Service Vulnerability
Published 2023-03-23 · Modified
8.6EPSS 0.010
CVE-2022-20678
Cisco IOS XE Software AppNav-XE Denial of Service Vulnerability
Published 2022-04-15 · Modified
8.6EPSS 0.010
CVE-2023-20227
A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain L2TP packets. An attacker could exploit this vulnerability by sending crafted L2TP packets to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
Published 2023-09-27 · Modified
8.6EPSS 0.007
CVE-2018-0154
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.
Published 2018-03-28 · Analyzed
7.8KEVEPSS 0.071
CVE-2018-0177
A vulnerability in the IP Version 4 (IPv4) processing code of Cisco IOS XE Software running on Cisco Catalyst 3850 and Cisco Catalyst 3650 Series Switches could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IPv4 packets. An attacker could exploit this vulnerability by sending specific IPv4 packets to an IPv4 address on an affected device. A successful exploit could allow the attacker to cause high CPU utilization, traceback messages, or a reload of the affected device that leads to a DoS condition. If the switch does not reboot when under attack, it would require manual intervention to reload the device. This vulnerability affects Cisco Catalyst 3850 and Cisco Catalyst 3650 Series Switches that are running Cisco IOS XE Software Release 16.1.1 or later, until the first fixed release, and are configured with an IPv4 address. Cisco Bug IDs: CSCvd80714.
Published 2018-03-28 · Modified
7.8EPSS 0.038
CVE-2020-3479
Cisco IOS and IOS XE Software MP-BGP EVPN Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.8EPSS 0.011
CVE-2020-3428
Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WLAN Local Profiling Denial of Service Vulnerability
Published 2020-09-24 · Modified
7.4EPSS 0.005
CVE-2022-20677
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.2EPSS 0.006
CVE-2020-3423
Cisco IOS XE Software Arbitrary Code Execution Vulnerability
Published 2020-09-24 · Modified
7.2EPSS 0.004
CVE-2021-1371
Cisco IOS XE SD-WAN Software Console Privilege Escalation Vulnerability
Published 2021-03-24 · Modified
7.2EPSS 0.003
CVE-2017-12319
A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. The vulnerability exists due to changes in the implementation of the BGP MPLS-Based Ethernet VPN RFC (RFC 7432) draft between IOS XE software releases. When the BGP Inclusive Multicast Ethernet Tag Route or BGP EVPN MAC/IP Advertisement Route update packet is received, it could be possible that the IP address length field is miscalculated. An attacker could exploit this vulnerability by sending a crafted BGP packet to an affected device after the BGP session was established. An exploit could allow the attacker to cause the affected device to reload or corrupt the BGP routing table; either outcome would result in a DoS. The vulnerability may be triggered when the router receives a crafted BGP message from a peer on an existing BGP session. This vulnerability affects all releases of Cisco IOS XE Software prior to software release 16.3 that support BGP EVPN configurations. If the device is not configured for EVPN, it is not vulnerable. Cisco Bug IDs: CSCui67191, CSCvg52875.
Published 2018-03-27 · Analyzed
7.1KEVEPSS 0.052
CVE-2018-0180
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
Published 2018-03-28 · Analyzed
7.1KEVEPSS 0.049
CVE-2018-0179
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
Published 2018-03-28 · Analyzed
7.1KEVEPSS 0.049
CVE-2017-12232
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through 15.6 could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to a misclassification of Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. Cisco Bug IDs: CSCvc03809.
Published 2017-09-28 · Analyzed
6.5KEVEPSS 0.022
CVE-2020-3299
Multiple Cisco Products SNORT HTTP Detection Engine File Policy Bypass Vulnerability
Published 2020-10-21 · Modified
5.8EPSS 0.023