Cisco Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Cisco products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

103

In CISA KEV

94

Beyond CISA KEV

9

Sensor Observed

3

Virtual Patch Available

1

Cisco KEVs Added by Year

Loading...

103 Cisco KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2017-6736

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

Confirmed In CISA 03 Mar 2022
CVE-2017-6737

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...

Confirmed In CISA 03 Mar 2022
CVE-2017-6738

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

Confirmed In CISA 03 Mar 2022
CVE-2017-6740

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

Confirmed In CISA 03 Mar 2022
CVE-2017-6743

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

Confirmed In CISA 03 Mar 2022
CVE-2017-6744

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an...

Confirmed In CISA 03 Mar 2022
CVE-2018-0151

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote...

Confirmed In CISA 03 Mar 2022
CVE-2018-0154

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an...

Confirmed In CISA 03 Mar 2022
CVE-2018-0155

A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst...

Confirmed In CISA 03 Mar 2022
CVE-2018-0156

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to...

Confirmed In CISA 03 Mar 2022
CVE-2018-0158

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an...

Confirmed In CISA 03 Mar 2022
CVE-2018-0159

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software...

Confirmed In CISA 03 Mar 2022
CVE-2018-0161

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst...

Confirmed In CISA 03 Mar 2022
CVE-2018-0167

Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and...

Confirmed In CISA 03 Mar 2022
CVE-2018-0172

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...

Confirmed In CISA 03 Mar 2022
CVE-2018-0173

A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4...

Confirmed In CISA 03 Mar 2022
CVE-2018-0174

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,...

Confirmed In CISA 03 Mar 2022
CVE-2018-0175

Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR...

Confirmed In CISA 03 Mar 2022
CVE-2018-0179

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...

Confirmed In CISA 03 Mar 2022
CVE-2018-0180

Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to...

Confirmed In CISA 03 Mar 2022
CVE-2019-1652

Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability

Confirmed In CISA 03 Mar 2022
CVE-2022-20699

Cisco Small Business RV Series Routers Vulnerabilities

Confirmed In CISA 03 Mar 2022
CVE-2022-20700

Cisco Small Business RV Series Routers Vulnerabilities

Confirmed In CISA 03 Mar 2022
CVE-2022-20701

Cisco Small Business RV Series Routers Vulnerabilities

Confirmed In CISA 03 Mar 2022
CVE-2022-20703

Cisco Small Business RV Series Routers Vulnerabilities

Confirmed In CISA 03 Mar 2022

Common Vulnerability Classes (CWE)

  • CWE-20 — Improper Input Validation 21
  • CWE-399 — Resource Management Errors 10
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 10
  • CWE-121 — Stack-based Buffer Overflow 6
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 5
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-287 — Improper Authentication 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology