Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers
ASR1000-ESP20
Chassis
· ASR 1000 series
Is the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers still supported?
No. Cisco ended support for the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers on 2021-04-30. No further security fixes will be issued. See Cisco's lifecycle bulletin.
When does the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers reach end of support?
Cisco support for the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers ends on 2021-04-30.
What replaces the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers?
Cisco has not published a successor model for the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers.
What known-exploited CVEs apply to the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers past end of support?
40 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers runs. These will not be patched on this device because it is past the Cisco security-support date. See the Known Exploited Vulnerabilities table below for the full list.
Known Exploited Vulnerabilities
This device is past Cisco's security-support date. 40 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. Cisco is not issuing patches for this model. Isolate, compensate, or refresh.
| CVE | KEV added | Vulnerability | Flags |
|---|---|---|---|
CVE-2008-4128
|
Cisco IOS Cross-Site Request Forgery Vulnerability | ||
CVE-2025-20352
|
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability | ||
CVE-2023-20273
|
Cisco IOS XE Web UI Command Injection Vulnerability | ||
CVE-2023-20198
|
Cisco IOS XE Web UI Privilege Escalation Vulnerability | ||
CVE-2023-20109
|
Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability | ||
CVE-2004-1464
|
Cisco IOS Denial-of-Service Vulnerability | ||
CVE-2016-6415
|
Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability | ||
CVE-2017-6742
|
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-3881
|
Cisco IOS and IOS XE Remote Code Execution Vulnerability | ||
CVE-2018-0180
|
Cisco IOS Software Denial-of-Service Vulnerability | ||
CVE-2018-0179
|
Cisco IOS Software Denial-of-Service Vulnerability | ||
CVE-2018-0175
|
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability | ||
CVE-2018-0174
|
Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability | ||
CVE-2018-0173
|
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability | ||
CVE-2018-0172
|
Cisco IOS and IOS XE Software Improper Input Validation Vulnerability | ||
CVE-2018-0167
|
Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability | ||
CVE-2018-0161
|
Cisco IOS Software Resource Management Errors Vulnerability | ||
CVE-2018-0159
|
Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability | ||
CVE-2018-0158
|
Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability | ||
CVE-2018-0156
|
Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability | ||
CVE-2018-0154
|
Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability | ||
CVE-2018-0151
|
Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability | ||
CVE-2017-6744
|
Cisco IOS Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-6743
|
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-6740
|
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-6739
|
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-6738
|
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-6737
|
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-6736
|
Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability | ||
CVE-2017-6663
|
Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability | ||
CVE-2017-6627
|
Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability | ||
CVE-2017-12319
|
Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability | ||
CVE-2017-12240
|
Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability | ||
CVE-2017-12237
|
Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability | ||
CVE-2017-12235
|
Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability | ||
CVE-2017-12234
|
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | ||
CVE-2017-12233
|
Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability | ||
CVE-2017-12232
|
Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability | ||
CVE-2017-12231
|
Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability | ||
CVE-2018-0171
|
Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability |
Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.
Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.
Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers Lifecycle Overview
The Cisco Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers (ASR1000-ESP20) is a chassis product in the Cisco ASR 1000 series. This product has reached end of life as of , meaning Cisco no longer provides technical support, software updates, or hardware replacement for this product. It was last available for purchase on . Organizations still running the Cisco ASR 1000 Series 5- and 10-Gbps Embedded Services Processors, ASR 1000 Series Route Processor (RP1), ASR 1000 Series 10Gbps SPA Interface Processor, and ASR 1001 and 1002 Routers should plan a migration .
Lifecycle Milestones
| Lifecycle notice published | 11y 3mo ago | |
|---|---|---|
| End of sale | 10y 3mo ago | |
| Last order date | 10y ago | |
| End of failure analysis | 9y 3mo ago | |
| Last date of support | 5y 3mo ago |