CVE-2018-0154: high-severity vulnerability in Cisco IOS
Published · Updated
51Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA.
ssvc Actcvss 7.5epss 7.1%
from disclosure to weapon
Published on NVDMar 28
CISA KEV+1436d
exploitation probability
7.1%top 6% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-03-17
Apply updates per vendor instructions.
In short
A flaw in Cisco's VPN security module allows attackers to send specially crafted network traffic that can freeze or crash the device, making it unavailable to users.
Technical detail
The vulnerability exists in the crypto engine of Cisco ISM-VPN on IOS Software due to improper handling of VPN traffic. An unauthenticated remote attacker can trigger a denial of service by sending crafted VPN packets, causing the device to hang or crash (CWE-399: Resource exhaustion).
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · Cisco IOS