CVE-2018-0154
KEVlargeUnauthenticated Remote DoS in Cisco IOS ISM-VPN Crypto Engine
CISA: Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability
A vulnerability in the crypto engine of Cisco's Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software allows an unauthenticated, remote attacker to hang or crash the affected router, causing a denial of service. The flaw (CWE-399, resource management) is caused by insufficient handling of VPN traffic and is triggered by sending crafted VPN traffic directly to an affected device, requiring no authentication, credentials, or user interaction. A successful exploit yields only availability impact — the device hangs or crashes — with no confidentiality or integrity impact per the CVSS 3.1 vector. Any organization running Cisco IOS on a device equipped with an ISM-VPN accelerator module and reachable for VPN traffic is affected. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 — and EPSS assigns a 7.1% (94th percentile) probability of exploitation in the next 30 days, though no public proof-of-concept is known and ransomware use is unknown.
What to do: Apply the fixed IOS releases identified in Cisco's advisory for Bug ID CSCvd39267 per vendor instructions. Inventory devices with 'show inventory' or similar to confirm whether an ISM-VPN module (ISM-VPN-100/300/800 class) is installed, and restrict IKE/ESP (VPN) traffic to trusted peers with ACLs or firewall rules as an interim mitigation. Prioritize patching internet-reachable routers acting as VPN endpoints, given the KEV listing and high EPSS score.
| Cisco IOS Software on devices with Integrated Services Module for VPN (ISM-VPN) installed | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.
- Affected
- Cisco IOS Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios
- Weakness
- CWE-399
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.