CVE-2018-0158
KEVmassUnauthenticated DoS via IKEv2 Memory Leak in Cisco IOS and IOS XE Software
CISA: Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE Software allows an unauthenticated, remote attacker to cause a memory leak or a device reload, resulting in a denial of service. The flaw stems from incorrect processing of certain IKEv2 packets (CWE-401 missing memory release; CWE-20 improper input validation) and is triggered by sending crafted IKEv2 packets to an affected device. A successful attack causes the device to continuously consume memory and eventually reload, disrupting VPN termination and any traffic routed through the device, with high availability impact but no confidentiality or integrity impact (CVSS 3.1: 8.6 High, AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). Affected organizations are those running Cisco IOS or IOS XE on routers, switches, or VPN gateways where IKEv2 processing is enabled and reachable, especially internet-facing edge devices. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03 and carries a 7.2% EPSS probability of exploitation within 30 days (94th percentile), though no public proof-of-concept is known.
What to do: Apply fixed Cisco IOS/IOS XE releases per the vendor's instructions for Bug ID CSCvf22394, as required by the CISA KEV catalog entry, and verify running releases against the Cisco advisory since affected ranges span many software trains. As interim mitigation, restrict reachability of IKEv2 (UDP 500 and 4500) from untrusted networks on devices that do not need to terminate IKEv2, and monitor memory utilization on internet-facing IOS/IOS XE devices with IKEv2 enabled.
| Cisco IOS | — |
| Cisco IOS XE | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a memory leak or a reload of an affected device that leads to a denial of service (DoS) condition. The vulnerability is due to incorrect processing of certain IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device to be processed. A successful exploit could cause an affected device to continuously consume memory and eventually reload, resulting in a DoS condition. Cisco Bug IDs: CSCvf22394.
- Affected
- Cisco IOS Software and Cisco IOS XE Software
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- cisco
- Products
- ios, ios xe
- Weakness
- CWE-20, CWE-401
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H