Junglewise Threat Intelligence

CVE-2018-0174: Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

CVE-2018-0174 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco Ios Software, Cisco IOS XE Software, Cisco IOS XE. Vendors: Rockwell Automation, Cisco.

Executive brief

A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS and IOS XE Software allows an unauthenticated, remote attacker to cause a denial of service (DoS) via a device reload. The issue stems from incomplete input validation of option 82 information received in DHCPv4 packets from relay agents.

Affected products

  • Cisco IOS Software up to (including) 15.2(6)e0a
  • Cisco IOS XE Software up to (including) 15.2(6)e0a
  • Rockwell Automation Allen-Bradley Stratix 5400/5410/5700/8000/8300

Timeline

  • 2018-03-28: advisory: Initial Cisco Security Advisory published
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-03: disclosed: NVD publication date

Related threats