Junglewise Threat Intelligence

CVE-2018-0156: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

CVE-2018-0156 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE Software, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in the Smart Install feature of Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. The flaw is due to improper validation of packet data sent to TCP port 4786, which can trigger a reload of affected client switches.

Affected products

  • Cisco IOS Software
  • Cisco IOS XE Software

Timeline

  • 2018-03-28: disclosed: Initial Cisco advisory publication date
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats