Executive brief
A vulnerability in the IKEv1 implementation of Cisco IOS and IOS XE Software allows an unauthenticated remote attacker to cause a device reload. The issue is caused by improper validation of crafted IKEv1 packets sent during negotiation, leading to a denial-of-service condition.
Affected products
- Cisco IOS Software
- Cisco IOS XE Software
Timeline
- 2018-03-28: advisory: Initial Cisco security advisory published
- 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-03: disclosed: NVD publication date
- 2022-03-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog