CVE-2018-0180: medium-severity vulnerability in Cisco IOS
Published · Updated
43Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA.
ssvc Attendcvss 6.8epss 4.9%
from disclosure to weapon
Published on NVDMar 28
CISA KEV+1436d
exploitation probability
4.9%top 8% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-03-17
Apply updates per vendor instructions.
In short
A flaw in Cisco IOS Software's login feature allows attackers to crash a device remotely without needing to log in, causing a service outage. This affects certain Cisco routers and switches running specific software versions.
Technical detail
Multiple vulnerabilities in the Login Enhancements feature of Cisco IOS allow unauthenticated remote attackers to trigger a system reload via crafted login requests. Affected versions include 15.4(2)T, 15.4(3)M, 15.4(2)CG and later; exploitation results in denial of service without requiring prior authentication or special privileges.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities affect Cisco devices that are running Cisco IOS Software Release 15.4(2)T, 15.4(3)M, or 15.4(2)CG and later. Cisco Bug IDs: CSCuy32360, CSCuz60599.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Affected products
n/a · Cisco IOS