Junglewise Threat Intelligence

CVE-2018-0151: Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

CVE-2018-0151 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE Software, Cisco Ios Software, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco.

Executive brief

A buffer overflow vulnerability in the Quality of Service (QoS) subsystem of Cisco IOS and IOS XE Software allows a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service. The flaw exists due to improper bounds checking on packets sent to UDP port 18999.

Affected products

  • Cisco IOS Software
  • Cisco IOS XE Software

Timeline

  • 2018-03-28: advisory: Initial Cisco Security Advisory published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed

Related threats