Hello,
My question seems simple in nature, but I cannot seem to get a good answer anywhere. I am trying to document all CVEs that relate to a given release of IOS (IOS 12.2 (40) SE in particular). After using Cisco's tool to find CVEs relating to that release I was left wondering if an unpatched IOS 12.2 40 SE would be vulnerable to more recently found vulnerabilities (with CVE numbers in NIST database) due to a shared code base. The only documention I could fins was the CiscoIOS Softweare Reference Guide (ver 1.0 OCT 2012) that mentioned all IOS S variants sharing a code base. My gut tells me that the code base is similar if not the same to mainline IOS, just with added functionality, so therfore new vulnerabilities with associated CVE would probably apply to 12.2SE as well provided it remained unpatched.
Please anybody with any insight into this, your comments would be more than welcome at this point, I'm pretty sure I've searched the entire internet.
Thanks,
~Dave