Junglewise Threat Intelligence

CVE-2018-0159: Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

CVE-2018-0159 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE Software, Cisco Ios Software, Cisco IOS XE. Vendors: Cisco.

Executive brief

A vulnerability in the IKEv1 implementation of Cisco IOS and IOS XE Software allows an unauthenticated remote attacker to cause a device reload. The issue is caused by improper validation of crafted IKEv1 packets sent during negotiation, leading to a denial-of-service condition.

Affected products

  • Cisco IOS Software
  • Cisco IOS XE Software

Timeline

  • 2018-03-28: advisory: Initial Cisco security advisory published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date
  • 2022-03-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog

Related threats