VendorsCiscoios15.3\(3\)ja1n
Vulnerabilities

Cisco IOS 15.3\(3\)ja1n

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2015-0635
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to spoof Autonomic Networking Registration Authority (ANRA) responses, and consequently bypass intended device and node access restrictions or cause a denial of service (disrupted domain access), via crafted AN messages, aka Bug ID CSCup62191.
Published 2015-03-26 · Modified
9.0EPSS 0.021
CVE-2019-1738
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2019-1739
Cisco IOS and IOS XE Software Network-Based Application Recognition Denial of Service Vulnerabilities
Published 2019-03-27 · Modified
8.6EPSS 0.025
CVE-2020-3225
Cisco IOS and IOS XE Software Common Industrial Protocol Denial of Service Vulnerabilities
Published 2020-06-03 · Modified
8.6EPSS 0.021
CVE-2015-0649
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.
Published 2015-03-26 · Modified
7.8EPSS 0.021
CVE-2015-0647
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) UDP packets, aka Bug ID CSCum98371.
Published 2015-03-26 · Modified
7.8EPSS 0.021
CVE-2015-0648
Memory leak in Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (memory consumption) via crafted Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun49658.
Published 2015-03-26 · Modified
7.8EPSS 0.021
CVE-2015-0636
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (disrupted domain access) via spoofed AN messages that reset a finite state machine, aka Bug ID CSCup62293.
Published 2015-03-26 · Modified
7.8EPSS 0.020
CVE-2016-6391
Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036.
Published 2016-10-05 · Modified
7.8EPSS 0.019
CVE-2015-0637
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS 12.2, 12.4, 15.0, 15.2, 15.3, and 15.4 and IOS XE 3.10.xS through 3.13.xS before 3.13.1S allows remote attackers to cause a denial of service (device reload) via spoofed AN messages, aka Bug ID CSCup62315.
Published 2015-03-26 · Modified
7.8EPSS 0.019
CVE-2015-0638
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3, when a VRF interface is configured, allows remote attackers to cause a denial of service (interface queue wedge) via crafted ICMPv4 packets, aka Bug ID CSCsi02145.
Published 2015-03-26 · Modified
7.1EPSS 0.017
CVE-2019-1757
Cisco IOS and IOS XE Software Smart Call Home Certificate Validation Vulnerability
Published 2019-03-28 · Modified
5.9EPSS 0.011
CVE-2017-12228
A vulnerability in the Cisco Network Plug and Play application of Cisco IOS 12.4 through 15.6 and Cisco IOS XE 3.3 through 16.4 could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data by using an invalid certificate. The vulnerability is due to insufficient certificate validation by the affected software. An attacker could exploit this vulnerability by supplying a crafted certificate to an affected device. A successful exploit could allow the attacker to conduct man-in-the-middle attacks to decrypt confidential information on user connections to the affected software. Cisco Bug IDs: CSCvc33171.
Published 2017-09-28 · Modified
5.9EPSS 0.010
CVE-2019-1758
Cisco IOS Software Catalyst 6500 Series 802.1x Authentication Bypass Vulnerability
Published 2019-03-28 · Modified
4.7EPSS 0.006
CVE-2019-1762
Cisco IOS and IOS XE Software Information Disclosure Vulnerability
Published 2019-03-28 · Modified
4.4EPSS 0.002