Junglewise Threat Intelligence

CVE-2018-0158: Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

CVE-2018-0158 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE Software, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to cause a memory leak or device reload. The issue is caused by incorrect processing of crafted IKEv2 packets, leading to a denial-of-service (DoS) condition.

Affected products

  • Cisco IOS 15.5(3)S1.1 through 15.5(3)S1.12
  • Cisco IOS XE

Timeline

  • 2018-03-28: disclosed: Initial vendor advisory published by Cisco
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date
  • 2022-03-17: other: CISA KEV required action due date

Related threats