CVE-2018-0179: medium-severity vulnerability in Cisco IOS
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
A flaw in Cisco IOS Software's Login Enhancements feature allows an attacker on the network to crash affected devices by sending specially crafted requests, causing them to restart and become temporarily unavailable.
Multiple resource exhaustion vulnerabilities in the Login Block feature of Cisco IOS Software allow unauthenticated remote attackers to trigger uncontrolled resource consumption via crafted network traffic, resulting in system reload and denial of service. Affects IOS versions 15.4(2)T, 15.4(3)M, 15.4(2)CG and later; exploitation requires network reachability to the affected device.
The full analysis of this CVE is available in Portuguese →