Junglewise Threat Intelligence

CVE-2018-0175: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

CVE-2018-0175 · Severity: critical · CVSS 8 · Exploited in the wild · Published 2022-03-03

Technologies: Cisco IOS, Cisco IOS XE, Cisco IOS XR. Vendors: Cisco, Rockwell Automation.

Executive brief

A format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE, and IOS XR Software allows an unauthenticated, adjacent attacker to cause a denial of service or execute arbitrary code with elevated privileges. The vulnerability is triggered by processing malicious LLDP packets.

Affected products

  • Cisco IOS up to (including) 15.6.3m1
  • Cisco IOS XE up to (including) 15.6.3m1
  • Cisco IOS XR 15.4(3)m4.1
  • Rockwell Automation Stratix 5400/5410/5700/5900/8000/8300

Timeline

  • 2018-03-28: disclosed: Initial Cisco advisory publication
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats