Cisco Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Cisco products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

103

In CISA KEV

94

Beyond CISA KEV

9

Sensor Observed

3

Virtual Patch Available

1

Cisco KEVs Added by Year

Loading...

103 Cisco KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2022-20708

Cisco Small Business RV Series Routers Vulnerabilities

Confirmed In CISA 03 Mar 2022
CVE-2009-2055

Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid...

Confirmed In CISA 25 Mar 2022
CVE-2010-3035

Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers...

Confirmed In CISA 25 Mar 2022
CVE-2015-0666

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers...

Confirmed In CISA 25 Mar 2022
CVE-2017-3881

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an...

Confirmed In CISA 25 Mar 2022
CVE-2018-0125

A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an...

Confirmed In CISA 25 Mar 2022
CVE-2018-0147

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an...

Confirmed In CISA 25 Mar 2022
CVE-2022-20821

Cisco IOS XR Software Health Check Open Port Vulnerability

Confirmed In CISA 23 May 2022
CVE-2016-6367

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges...

Confirmed In CISA 24 May 2022
CVE-2016-6366

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv,...

Confirmed In CISA 24 May 2022
CVE-2019-15271

Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Arbitrary Command Execution Vulnerability

Confirmed In CISA 08 Jun 2022
CVE-2020-3153

Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Confirmed In CISA 24 Oct 2022
CVE-2020-3433

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Confirmed In CISA 24 Oct 2022
CVE-2017-6742

A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely...

Confirmed In CISA 19 Apr 2023
CVE-2016-6415

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x,...

Confirmed In CISA 19 May 2023
CVE-2004-1464

Cisco IOS 12.2(15) and earlier allows remote attackers to cause a denial of service (refused VTY (virtual terminal) connections), via a crafted TCP...

Confirmed In CISA 19 May 2023
CVE-2023-20269

A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...

Confirmed In CISA 13 Sep 2023
CVE-2023-20109

A vulnerability in the Cisco Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS Software and Cisco IOS XE Software could allow an...

Confirmed In CISA 10 Oct 2023
CVE-2023-20198

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are...

Confirmed In CISA 16 Oct 2023
CVE-2023-20273

A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands with the privileges...

Confirmed In CISA 23 Oct 2023
CVE-2020-3259

Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

Confirmed In CISA 15 Feb 2024
CVE-2024-20353

A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD)...

Confirmed In CISA 24 Apr 2024
CVE-2024-20359

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive...

Confirmed In CISA 24 Apr 2024
CVE-2024-20399

Cisco NX-OS Software CLI Command Injection Vulnerability

Confirmed In CISA 02 Jul 2024
CVE-2024-20481

A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense...

Confirmed In CISA 24 Oct 2024

Common Vulnerability Classes (CWE)

  • CWE-20 — Improper Input Validation 21
  • CWE-399 — Resource Management Errors 10
  • CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 10
  • CWE-121 — Stack-based Buffer Overflow 6
  • CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 5
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
  • CWE-287 — Improper Authentication 3

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology