Skip to content
COOEY

FAIL › dossier

IOS

PRODUCT

· dossier confidence 20%

IOS and Apple iOS both demonstrate a concerning track record of high-severity remote code execution vulnerabilities, with IOS plagued by decades-old unpatched flaws actively exploited in the wild and Apple iOS suffering repeated WebKit memory corruption and type confusion bugs. Organizations relying on either platform face significant risk from legacy vulnerabilities and frequent memory safety issues in core components.

PROFILE
CategoryOperating SystemWhat they doInternetwork Operating System (IOS) is the operating system used on Cisco networking equipment such as routers, switches, and firewalls. Apple iOS is a mobile operating system developed by Apple Inc. for smartphones, tablets, and wearables. Websitehttps://www.cisco.com/c/en/us/products/ios-software.html ↗
SECURITY POSTURE

Both IOS and Apple iOS have a history of high-severity remote code execution (RCE) vulnerabilities, with IOS suffering from decades-old unpatched flaws actively exploited in the wild, and Apple iOS experiencing repeated WebKit memory corruption and type confusion bugs leading to code execution.

Notable failures
  • CVE-2008-4128: Decades-old Cisco IOS CSRF RCE actively exploited
  • CVE-2022-42856: Apple iOS type confusion RCE
  • CVE-2021-30761: Apple iOS WebKit memory corruption RCE
  • CVE-2019-7287: Apple iOS memory corruption RCE
  • CVE-2017-6744: Cisco IOS SNMP RCE
  • CVE-2016-4656: Apple iOS kernel memory corruption RCE
Patterns: Repeated unpatched legacy IOS vulnerabilities exploited years after disclosure; Frequent WebKit memory corruption and type confusion RCEs in Apple iOS; High-severity RCEs in network protocol implementations (SNMP, CIP, PN-DCP) on IOS
FAILURE HISTORY · 20
DATEEVENTSEVSUMMARY
2022-05-24 CVE-2016-4657 high Apple iOS WebKit memory corruption flaw allows remote code execution via malicious websites.
2022-05-24 CVE-2016-4656 high A memory corruption vulnerability in the iOS kernel allowed attackers to execute privileged code or cause DoS via a crafted app.
2022-05-24 CVE-2016-4655 high An iOS kernel vulnerability allowed attackers to read sensitive memory data via a crafted app, and it was actively exploited in the wild.
2022-03-03 CVE-2018-0180 high A decades-old Cisco IOS DoS vulnerability (CVE-2018-0180) remains actively exploited in the wild, proving that unpatched legacy hardware is a critical compliance failure.
2021-11-03 CVE-2021-30762 high Apple iOS WebKit use-after-free flaw allows remote code execution via malicious web content.
2021-11-03 CVE-2021-30761 high Apple iOS WebKit memory corruption vulnerability allows remote code execution via malicious web content.
2021-11-03 CVE-2021-30666 high Apple iOS WebKit buffer overflow allows remote code execution via malicious web content.
2022-05-23 CVE-2019-7287 high Apple iOS memory corruption vulnerability allows remote code execution and is actively exploited in the wild.
2022-03-03 CVE-2017-6744 high Cisco IOS software contained an SNMP remote code execution vulnerability allowing authenticated attackers to execute arbitrary code or reload systems via crafted packets.
2023-05-19 CVE-2004-1464 high Cisco IOS Denial-of-Service Vulnerability
2022-12-14 CVE-2022-42856 high Apple iOS had an active web content execution flaw
2026-07-13 CVE-2008-4128 high Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution.
2022-03-03 CVE-2017-12235 high An unauthenticated remote attacker could cause Cisco Industrial Ethernet switches to reload via a PROFINET protocol vulnerability, causing denial of service.
2022-03-03 CVE-2018-0154 high Cisco ISM-VPN crypto engine DoS vulnerability allowed unauthenticated remote attackers to crash devices, marking it as actively exploited in the KEV catalog.
2022-03-03 CVE-2018-0161 high Cisco IOS Software SNMP subsystem allowed authenticated remote attackers to cause denial-of-service via resource management errors.
2022-03-03 CVE-2018-0179 high Cisco IOS Software's Login Enhancements feature allowed unauthenticated remote attackers to trigger system reloads via a DoS vulnerability.
2022-03-03 CVE-2017-12232 high An unauthenticated adjacent attacker could force Cisco ISR G2 routers to reload via a DoS vulnerability in Cisco IOS.
2022-03-03 CVE-2017-12234 high Cisco IOS CIP vulnerability allows remote denial-of-service via unauthenticated requests causing device reloads.
2022-03-03 CVE-2017-12233 high Cisco IOS CIP vulnerability allows remote denial-of-service via unauthenticated requests causing device reloads.
2022-03-03 CVE-2017-12231 high Cisco IOS NAT DoS vulnerability allowed unauthenticated remote attackers to cause denial of service.
Open questions: Exact founding year of Cisco IOS · Specific headquarters location for Cisco IOS development
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-18 04:09:54.904046+00:00