Junglewise Threat Intelligence

CVE-2018-0167: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

CVE-2018-0167 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco, Rockwell Automation.

Executive brief

Multiple buffer overflow vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE, and IOS XR software. An unauthenticated, adjacent attacker could exploit these by sending crafted LLDP packets to cause a denial of service or execute arbitrary code with elevated privileges.

Affected products

  • Cisco IOS up to (including) 15.6.3m1
  • Cisco IOS XE up to (including) 15.6.3m1
  • Cisco IOS XR 4.1 up to (excluding) 5.1.3
  • Rockwell Automation Stratix 5400/5410/5700/5900/8000/8300

Timeline

  • 2018-03-28: disclosed: Initial Cisco Security Advisory date
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: other: Published to NVD
  • 2022-03-17: other: CISA KEV due date for remediation

Related threats