VendorsCiscoios15.6\(3\)m2a
Vulnerabilities

Cisco IOS 15.6\(3\)m2a

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2017-6744
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities.
Published 2017-07-17 · Analyzed
9.0KEVEPSS 0.073
CVE-2020-3217
Cisco IOS, IOS XE, IOS XR, and NX-OS Software One Platform Kit Remote Code Execution Vulnerability
Published 2020-06-03 · Modified
8.8EPSS 0.011
CVE-2019-1751
Cisco IOS Software NAT64 Denial of Service Vulnerability
Published 2019-03-28 · Modified
8.6EPSS 0.025
CVE-2019-1752
Cisco IOS and IOS XE Software ISDN Interface Denial of Service Vulnerability
Published 2019-03-28 · Modified
8.6EPSS 0.025
CVE-2020-3228
Cisco IOS, IOS XE, and NX-OS Software Security Group Tag Exchange Protocol Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.018
CVE-2020-3226
Cisco IOS and IOS XE Software Session Initiation Protocol Denial of Service Vulnerability
Published 2020-06-03 · Modified
8.6EPSS 0.016
CVE-2024-20311
A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload. This vulnerability is due to the incorrect handling of LISP packets. An attacker could exploit this vulnerability by sending a crafted LISP packet to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Note: This vulnerability could be exploited over either IPv4 or IPv6 transport.
Published 2024-03-27 · Analyzed
8.6EPSS 0.008
CVE-2021-1620
Cisco IOS and IOS XE Software IKEv2 AutoReconnect Feature Denial of Service Vulnerability
Published 2021-09-23 · Analyzed
7.7EPSS 0.011
CVE-2025-20174
A vulnerability in the SNMP subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper error handling when parsing SNMP requests. An attacker could exploit this vulnerability by sending a crafted SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.  This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMP v2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMP v3, the attacker must have valid SNMP user credentials for the affected system.
Published 2025-02-05 · Analyzed
7.7EPSS 0.008
CVE-2022-20724
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.6EPSS 0.013
CVE-2022-20727
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
7.2EPSS 0.011
CVE-2017-6663
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in a denial of service (DoS) condition. More Information: CSCvd88936. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
Published 2017-08-07 · Analyzed
6.5KEVEPSS 0.021
CVE-2018-0163
A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error introduced into the code. An attacker could exploit this vulnerability by trying to access an 802.1x multi-auth port after a successful supplicant has authenticated. An exploit could allow the attacker to bypass the 802.1x access controls and obtain access to the network. Cisco Bug IDs: CSCvg69701.
Published 2018-03-28 · Modified
6.5EPSS 0.006
CVE-2017-6665
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to reset the Autonomic Control Plane (ACP) of an affected system and view ACP packets that are transferred in clear text within an affected system, an Information Disclosure Vulnerability. More Information: CSCvd51214. Known Affected Releases: Denali-16.2.1 Denali-16.3.1.
Published 2017-08-07 · Modified
6.5EPSS 0.004
CVE-2019-1757
Cisco IOS and IOS XE Software Smart Call Home Certificate Validation Vulnerability
Published 2019-03-28 · Modified
5.9EPSS 0.011
CVE-2021-1377
Cisco IOS and IOS XE Software ARP Resource Management Exhaustion Denial of Service Vulnerability
Published 2021-03-24 · Modified
5.8EPSS 0.014
CVE-2022-20725
Cisco IOx Application Hosting Environment Vulnerabilities
Published 2022-04-15 · Modified
5.5EPSS 0.006
CVE-2019-1762
Cisco IOS and IOS XE Software Information Disclosure Vulnerability
Published 2019-03-28 · Modified
4.4EPSS 0.002