ZeroHour

CVE-2018-0158

KEVmass

Unauthenticated DoS via IKEv2 Memory Leak in Cisco IOS and IOS XE Software

CISA: Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

CVSS 3.1
8.6 high
EPSS
7%p94
Published
()
KEV added
AI analysis

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE Software allows an unauthenticated, remote attacker to cause a memory leak or a device reload, resulting in a denial of service. The flaw stems from incorrect processing of certain IKEv2 packets (CWE-401 missing memory release; CWE-20 improper input validation) and is triggered by sending crafted IKEv2 packets to an affected device. A successful attack causes the device to continuously consume memory and eventually reload, disrupting VPN termination and any traffic routed through the device, with high availability impact but no confidentiality or integrity impact (CVSS 3.1: 8.6 High, AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). Affected organizations are those running Cisco IOS or IOS XE on routers, switches, or VPN gateways where IKEv2 processing is enabled and reachable, especially internet-facing edge devices. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03 and carries a 7.2% EPSS probability of exploitation within 30 days (94th percentile), though no public proof-of-concept is known.

What to do: Apply fixed Cisco IOS/IOS XE releases per the vendor's instructions for Bug ID CSCvf22394, as required by the CISA KEV catalog entry, and verify running releases against the Cisco advisory since affected ranges span many software trains. As interim mitigation, restrict reachability of IKEv2 (UDP 500 and 4500) from untrusted networks on devices that do not need to terminate IKEv2, and monitor memory utilization on internet-facing IOS/IOS XE devices with IKEv2 enabled.

Affected
Cisco IOS
Cisco IOS XE
Estimated exposure
masshundreds of thousands of devices (subset of a multi-million-device Cisco IOS/IOS XE installed base; the exploitable subset is IKEv2-enabled, reachable edge/VPN… — Cisco IOS and IOS XE are among the most widely deployed network operating systems worldwide (millions of routers and switches), and public internet scans have long shown hundreds of thousands of Cisco IOS devices exposed, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.

CISA Known Exploited Vulnerability
Affected
Cisco IOS Software and Cisco IOS XE Software
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
cisco
Products
ios, ios xe
Weakness
CWE-20, CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

In the news