Junglewise Threat Intelligence

CVE-2018-0172: Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

CVE-2018-0172 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE Software, Cisco Ios Software, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco, Rockwell Automation.

Executive brief

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to cause a heap overflow. This occurs due to incomplete input validation of option 82 information in DHCPv4 packets, potentially leading to a device reload and denial-of-service (DoS) condition.

Affected products

  • Cisco IOS Software
  • Cisco IOS XE Software
  • Rockwell Automation Allen-Bradley ArmorStratix 5700
  • Rockwell Automation Allen-Bradley Stratix 5400
  • Rockwell Automation Allen-Bradley Stratix 5410
  • Rockwell Automation Allen-Bradley Stratix 5700
  • Rockwell Automation Allen-Bradley Stratix 8000
  • Rockwell Automation Allen-Bradley Stratix 8300

Timeline

  • 2018-03-28: advisory: Cisco published the initial security advisory.
  • 2022-03-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: disclosed: Publication date listed in the advisory.
  • 2022-03-03: exploited: Confirmed as exploited in the wild per CISA KEV entry.

Related threats