ZeroHour

CVE-2018-0156

KEVmass

Unauthenticated DoS in Cisco IOS/IOS XE Smart Install clients

CISA: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

CVSS 3.1
7.5 high
EPSS
9%p95
Published
()
KEV added
AI analysis

CVE-2018-0156 is an improper input-validation flaw (CWE-20) in the Smart Install feature of Cisco IOS and IOS XE that lets an unauthenticated, remote attacker force an affected switch to reload. The attacker sends a single crafted TCP packet to port 4786, the Smart Install listener, and the device crashes and reboots, producing a denial of service with no credentials or user interaction required. Impact is availability-only (CVSS 3.1:7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H): the attacker gains no code execution or data theft, only the ability to repeatedly knock devices offline. Only switches operating as Smart Install clients are affected; devices configured as Smart Install directors, or without the feature enabled, are not vulnerable. CISA added the flaw to the KEV catalog on 2022-03-03 (ransomware use unknown), EPSS rates 30-day exploitation probability at 8.6% (95th percentile), and no public PoC is known.

What to do: Apply updated IOS/IOS XE releases per Cisco's instructions for bug CSCvd40673 (CISA's required action). As an interim mitigation, restrict TCP port 4786 with ACLs to trusted Smart Install directors, and inventory which switches actually run as Smart Install clients since director-only devices are unaffected. Prioritize internet-reachable switches given the March 2022 KEV listing.

Affected
Cisco IOS (Smart Install client switches)
Cisco IOS XE (Smart Install client switches)
Estimated exposure
masson the order of 100,000+ internet-exposed Smart Install client switches, with a larger count including internal-only deployments — Public internet-wide scans of TCP port 4786 (Shodan/Censys) have historically shown on the order of 100,000+ Smart Install-enabled Cisco devices, and the broader base of IOS/IOS XE switches deployed behind firewalls is likely higher; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.

CISA Known Exploited Vulnerability
Affected
Cisco IOS Software and Cisco IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-399, CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news