Home/Cisco/network convergence system 5000 series/NCS-5002

NCS-5002

Announced in: Cisco NCS 5002 Series Router

Cisco Router · network convergence system 5000 series

Suggest a correction

NCS-5002 is aging. Support window is narrowing. Cisco support ends (+543d).

Is the Cisco NCS 5002 Series Router still supported?

Yes, but the support window is narrowing. Cisco support for the Cisco NCS 5002 Series Router ends on 2028-03-31. Plan refresh cycles now. See Cisco's lifecycle bulletin.

When does the Cisco NCS 5002 Series Router reach end of support?

Cisco support for the Cisco NCS 5002 Series Router ends on 2028-03-31.

What replaces the Cisco NCS 5002 Series Router?

Cisco has not published a successor model for the Cisco NCS 5002 Series Router.

What known-exploited CVEs apply to the NCS-5002 past end of support?

9 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform the Cisco NCS 5002 Series Router runs. These will not be patched on this device because it is past the Cisco security-support date. See the Known Exploited Vulnerabilities table below for the full list.

Known Exploited Vulnerabilities

This device is past Cisco's security-support date. 9 CVEs in CISA's Known Exploited Vulnerabilities catalog apply to the platform it runs. Cisco is not issuing patches for this model. Isolate, compensate, or refresh.

CVE KEV added Vulnerability Flags
CVE-2016-6415 Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
CVE-2022-20821 Cisco IOS XR Open Port Vulnerability
CVE-2010-3035 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
CVE-2009-2055 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability
CVE-2018-0175 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
CVE-2018-0167 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability
CVE-2020-3118 Cisco IOS XR Software Discovery Protocol Format String Vulnerability
CVE-2020-3566 Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
CVE-2020-3569 Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Source: CISA Known Exploited Vulnerabilities catalog. The Ransomware flag reflects CISA's own knownRansomwareCampaignUse field, set when the CVE has been observed in ransomware campaigns per their threat intel. It's not a property of the vulnerability description itself.

Correlation is at the platform level, not per-OS-version. Not exhaustive: KEV only lists actively-exploited CVEs and many relevant unexploited vulnerabilities are not here. Verify against vendor security advisories (PSIRT, JSA, PAN-SA) and NVD before acting. See compensating controls if refresh isn't immediate.

NCS-5002 Lifecycle Overview

The Cisco NCS-5002 (NCS-5002) is a router product in the Cisco network convergence system 5000 series. Cisco has announced that the NCS-5002 will reach end of sale on . Vendor support will continue until .

Lifecycle Milestones

Lifecycle notice published 4y 1mo ago
End of sale 3y 7mo ago
Last order date 3y 4mo ago
End of software maintenance 2y 7mo ago
End of failure analysis 2y 7mo ago
End of security vulnerability support 7mo ago
Last date of support in 1y 6mo
Description

Cisco NCS 5002 Series Router

Applicable Platforms
↑ Top