Executive brief
A vulnerability in the Smart Install feature of Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to trigger a buffer overflow by sending crafted packet data to TCP port 4786. Successful exploitation can lead to arbitrary code execution, a device reload, or an indefinite loop causing a watchdog crash.
Affected products
- Cisco IOS
- Cisco IOS XE
Timeline
- 2018-03-28: disclosed: Initial Cisco Security Advisory published
- 2018-04-24: other: Initial NVD analysis completed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV entry