ZeroHour

CVE-2018-0154

KEVlarge

Unauthenticated Remote DoS in Cisco IOS ISM-VPN Crypto Engine

CISA: Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
KEV added
AI analysis

A vulnerability in the crypto engine of Cisco's Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software allows an unauthenticated, remote attacker to hang or crash the affected router, causing a denial of service. The flaw (CWE-399, resource management) is caused by insufficient handling of VPN traffic and is triggered by sending crafted VPN traffic directly to an affected device, requiring no authentication, credentials, or user interaction. A successful exploit yields only availability impact — the device hangs or crashes — with no confidentiality or integrity impact per the CVSS 3.1 vector. Any organization running Cisco IOS on a device equipped with an ISM-VPN accelerator module and reachable for VPN traffic is affected. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-03 — and EPSS assigns a 7.1% (94th percentile) probability of exploitation in the next 30 days, though no public proof-of-concept is known and ransomware use is unknown.

What to do: Apply the fixed IOS releases identified in Cisco's advisory for Bug ID CSCvd39267 per vendor instructions. Inventory devices with 'show inventory' or similar to confirm whether an ISM-VPN module (ISM-VPN-100/300/800 class) is installed, and restrict IKE/ESP (VPN) traffic to trusted peers with ACLs or firewall rules as an interim mitigation. Prioritize patching internet-reachable routers acting as VPN endpoints, given the KEV listing and high EPSS score.

Affected
Cisco IOS Software on devices with Integrated Services Module for VPN (ISM-VPN) installed
Estimated exposure
large≈ tens of thousands of routers (10k–100k range, estimated) — ISM-VPN accelerator modules ship in Cisco 3900-series Integrated Services Routers, an installed base of enterprise branch/edge routers where VPN termination is commonly exposed to the internet, making tens of thousands of VPN-active…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient handling of VPN traffic by the affected device. An attacker could exploit this vulnerability by sending crafted VPN traffic to an affected device. A successful exploit could allow the attacker to cause the affected device to hang or crash, resulting in a DoS condition. Cisco Bug IDs: CSCvd39267.

CISA Known Exploited Vulnerability
Affected
Cisco IOS Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios
Weakness
CWE-399
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.