Junglewise Threat Intelligence

CVE-2018-0154: Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

CVE-2018-0154 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software allows an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. The issue is caused by insufficient handling of crafted VPN traffic, which can lead to a device hang or crash.

Affected products

  • Cisco IOS Software
  • Cisco Integrated Services Module for VPN (ISM-VPN)

Timeline

  • 2018-03-28: advisory: Original Cisco advisory date (from URL)
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed

Related threats