cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1073
Views
1
Helpful
2
Replies

IOS software checker vs. CVRF

Infosim
Level 1
Level 1

Hi,

I've noticed that the data provided by the IOS software checker sometimes is different from the data provided by the CVRF files. For example the CVRF of advisory cisco-sa-20151218-ios states that IOS 15.5(3)M1 is affected, but the software checker states, that it is not.

For my use case I don't need to check vulnerabilities for one or some IOS versions, but I want to know which versions are affected by a vulnerability so I have to rely on the CVRF files.


I think this is a known issue and wanted to ask if we can expect a solution soon?

2 Replies 2

Omar Santos
Cisco Employee
Cisco Employee

Hi Stefan,

This is a known issue. The best course of action is to use the IOS Software checker integration with the API. CVRF files have limited support for software versions.

CMurphy24
Level 1
Level 1

This seems to be a known issue - I logged a TAC and received the following response:  

 

In this case, I would suggest you to use the following Cisco IOS Software Checker since it is a reliable source from Cisco: https://tools.cisco.com/security/center/softwarechecker.x