ISC Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for ISC products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
105
In CISA KEV
95
Beyond CISA KEV
10
Sensor Observed
3
Virtual Patch Available
1
ISC KEVs Added by Year
105 ISC KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2017-6627
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote... |
Cisco IOS and Cisco IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6663
A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6736
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6737
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely... |
IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6738
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Cisco IOS XE Software | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6740
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6743
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2017-6744
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an... |
IOS, Universal Product | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0151
A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0154
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0155
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0156
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0158
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0159
A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0161
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0167
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and... |
Cisco IOS, IOS XE, and IOS XR | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0172
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0173
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0174
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated,... |
Cisco IOS and IOS XE | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0175
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR... |
Cisco IOS, IOS XE, and IOS XR | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0179
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2018-0180
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to... |
Cisco IOS | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2019-1652
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-20699
Cisco Small Business RV Series Routers Vulnerabilities |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2022-20700
Cisco Small Business RV Series Routers Vulnerabilities |
Cisco Small Business RV Series Router Firmware | Confirmed | In CISA | 03 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-20 — Improper Input Validation 21
- CWE-399 — Resource Management Errors 10
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 10
- CWE-121 — Stack-based Buffer Overflow 6
- CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor 5
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-287 — Improper Authentication 3
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology