CVE-2018-0156
KEVmassUnauthenticated DoS in Cisco IOS/IOS XE Smart Install clients
CISA: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability
CVE-2018-0156 is an improper input-validation flaw (CWE-20) in the Smart Install feature of Cisco IOS and IOS XE that lets an unauthenticated, remote attacker force an affected switch to reload. The attacker sends a single crafted TCP packet to port 4786, the Smart Install listener, and the device crashes and reboots, producing a denial of service with no credentials or user interaction required. Impact is availability-only (CVSS 3.1:7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H): the attacker gains no code execution or data theft, only the ability to repeatedly knock devices offline. Only switches operating as Smart Install clients are affected; devices configured as Smart Install directors, or without the feature enabled, are not vulnerable. CISA added the flaw to the KEV catalog on 2022-03-03 (ransomware use unknown), EPSS rates 30-day exploitation probability at 8.6% (95th percentile), and no public PoC is known.
What to do: Apply updated IOS/IOS XE releases per Cisco's instructions for bug CSCvd40673 (CISA's required action). As an interim mitigation, restrict TCP port 4786 with ACLs to trusted Smart Install directors, and inventory which switches actually run as Smart Install clients since director-only devices are unaffected. Prioritize internet-reachable switches given the March 2022 KEV listing.
| Cisco IOS (Smart Install client switches) | — |
| Cisco IOS XE (Smart Install client switches) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper validation of packet data. An attacker could exploit this vulnerability by sending a crafted packet to an affected device on TCP port 4786. Only Smart Install client switches are affected. Cisco devices that are configured as a Smart Install director are not affected by this vulnerability. Cisco Bug IDs: CSCvd40673.
- Affected
- Cisco IOS Software and Cisco IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-399, CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H